First published: Mon Sep 30 2019(Updated: )
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpbb Phpbb | <=3.1.7 | |
Debian Debian Linux | =8.0 | |
composer/phpbb/phpbb | <3.1.7-PL1 | 3.1.7-PL1 |
<=3.1.7 | ||
=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-16993.
The severity of CVE-2019-16993 is high with a severity value of 8.8.
The affected software for CVE-2019-16993 is phpBB before 3.1.7-PL1 and Debian Linux 8.0.
The CWE category for CVE-2019-16993 is CWE-352.
To fix CVE-2019-16993, it is recommended to update to phpBB version 3.1.7-PL1 or later.