CVE-2019-16108: Code Injection
Published Mar 19, 2020
·Updated
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
Affected Software
2 affected componentsFixes available
composer/phpbb/phpbb=3.2.7
3.2.8
phpBB phpbb=3.2.7
Remediation
Patch Available
Event History
Mar 19, 2020
CVE Published
via MITRE·11:03 PM
Data Sourced
via MITRE·11:03 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:12 PM
Frequently Asked Questions
1
What is the vulnerability ID for phpBB 3.2.7?
The vulnerability ID for phpBB 3.2.7 is CVE-2019-16108.
2
What is the severity level of CVE-2019-16108?
The severity level of CVE-2019-16108 is high.
3
How does CVE-2019-16108 impact phpBB?
CVE-2019-16108 allows an attacker to add an arbitrary CSS token sequence to a page through BBCode, potentially leading to CSS injection and various types of attacks.
4
How can I fix the vulnerability in phpBB 3.2.7?
To fix the vulnerability in phpBB 3.2.7, it is recommended to update to a version that addresses the issue.
5
Where can I find more information about CVE-2019-16108?
You can find more information about CVE-2019-16108 at https://www.phpbb.com/community/viewtopic.php?t=2523271.