CVE-2026-48613: SQL Injection
SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution of arbitrary SQL queries. Only applies to phpBB forums that had been updated from versions prior to phpBB 3.3.8 and have not been updated to 3.3.11 or newer yet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
phpBBto a version that resolves this vulnerability.Fixed in 3.3.11
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48613?
The severity of CVE-2026-48613 is classified as high with a score of 7.1.
How do I fix CVE-2026-48613?
To fix CVE-2026-48613, update your phpBB installation to the latest version that addresses this vulnerability.
What types of attacks can CVE-2026-48613 be exploited for?
CVE-2026-48613 can be exploited to execute arbitrary SQL queries against the phpBB database due to SQL injection.
Which versions of phpBB are affected by CVE-2026-48613?
CVE-2026-48613 affects phpBB forums that were updated from versions prior to phpBB 3.3.8 and have not been further updated.
What is the impact of CVE-2026-48613 on phpBB users?
The impact of CVE-2026-48613 on phpBB users includes potential unauthorized access to sensitive data and manipulation of the database.