CVE-2019-16993: CSRF
Published Sep 30, 2019
·Updated
In phpBB before 3.1.7-PL1, includes/acp/acpbbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.
Affected Software
3 affected componentsFixes available
composer/phpbb/phpbb<3.1.7-PL1
3.1.7-PL1
phpBB phpbb<=3.1.7
Debian Debian Linux=8.0
Remediation
Event History
Sep 30, 2019
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
Description
May 24, 2022
Advisory Published
via GitHub·04:57 PM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-16993.
2
What is the severity of CVE-2019-16993?
The severity of CVE-2019-16993 is high with a severity value of 8.8.
3
What is the affected software for CVE-2019-16993?
The affected software for CVE-2019-16993 is phpBB before 3.1.7-PL1 and Debian Linux 8.0.
4
What is the CWE category for CVE-2019-16993?
The CWE category for CVE-2019-16993 is CWE-352.
5
How can I fix CVE-2019-16993?
To fix CVE-2019-16993, it is recommended to update to phpBB version 3.1.7-PL1 or later.