CVE-2020-5501: CSRF
Published Jan 14, 2020
·Updated
phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.
Affected Software
2 affected componentsFixes available
composer/phpbb/phpbb=3.2.8
3.2.9
phpBB phpbb=3.2.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/phpbb/phpbbto a version that resolves this vulnerability.Fixed in 3.2.9
Event History
Jan 14, 2020
CVE Published
via MITRE·11:57 PM
Data Sourced
via MITRE·11:57 PM
Description
Jan 15, 2020
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
via GitHub·05:06 PM
Frequently Asked Questions
1
What is the vulnerability ID for the CSRF attack on phpBB 3.2.8?
The vulnerability ID for the CSRF attack on phpBB 3.2.8 is CVE-2020-5501.
2
What is the severity of CVE-2020-5501?
CVE-2020-5501 has a severity level of medium, with a severity value of 4.3.
3
How does CVE-2020-5501 affect phpBB 3.2.8?
CVE-2020-5501 allows a CSRF attack that can modify a group avatar in phpBB 3.2.8.
4
How can I fix the CSRF vulnerability in phpBB 3.2.8?
To fix the CSRF vulnerability in phpBB 3.2.8, update to a version that includes a fix for the vulnerability.
5
Where can I find more information about CVE-2020-5501?
You can find more information about CVE-2020-5501 in the following references: [Link 1](https://blog.phpbb.com/category/security/), [Link 2](https://www.phpbb.com/community/viewtopic.php?f=14&t=2534536).