Description
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1942-1 | phpbb3 security update |
Debian DLA |
DLA-1942-2 | phpbb3 regression update |
EUVD |
EUVD-2022-5363 | In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them. |
Github GHSA |
GHSA-vj3x-vfm4-hvxc | phpBB Cross-Site Request Forgery (CSRF) |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:24:48.712Z
Reserved: 2019-09-30T00:00:00.000Z
Link: CVE-2019-16993
No data.
Status : Modified
Published: 2019-09-30T12:15:10.860
Modified: 2024-11-21T04:31:30.007
Link: CVE-2019-16993
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA