CVE-2023-5917: phpBB Smiley Pack acp_icons.php main cross site scripting
A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the function main of the file phpBB/includes/acp/acpicons.php of the component Smiley Pack Handler. The manipulation of the argument pack leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 3.3.11 is able to address this issue. The patch is named ccf6e6c255d38692d72fcb613b113e6eaa240aac. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-244307.
Other sources
A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the function main of the file phpBB/includes/acp/acpicons.php of the component Smiley Pack Handler. The manipulation of the argument pak leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 3.3.11 is able to address this issue. The patch is named ccf6e6c255d38692d72fcb613b113e6eaa240aac. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-244307.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-5917.
What is the severity of CVE-2023-5917?
The severity of CVE-2023-5917 is medium.
Which software versions are affected by CVE-2023-5917?
The vulnerability affects phpBB up to version 3.3.10.
What is the CWE of CVE-2023-5917?
The CWE of CVE-2023-5917 is CWE-79.
How can I fix CVE-2023-5917?
To fix CVE-2023-5917, update phpBB to version 3.3.11 or higher.