CRITICAL9.8
GHSA-5cvh-xqhr-5g87
phpBB vulnerability related to use of "forum id" in circumstances related to a "global announcement."
Quick fix
GHSA-5cvh-xqhr-5g87 — phpbb/phpbb: upgrade to the fixed version with the command below.
composer require phpbb/phpbb:^3.0.5Details
Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances related to a "global announcement."
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2010-1630[ADVISORY]
- https://github.com/phpbb/phpbb-app/commit/1758aa38b21f5960ab1b1a241546b34a203051b6[WEB]
- https://github.com/phpbb/phpbb-app[PACKAGE]
- http://github.com/phpbb/phpbb3/commit/4ea3402f9363c9259881bc8ea6ce7fc6cb212657[WEB]
- http://www.openwall.com/lists/oss-security/2010/05/16/1[WEB]
- http://www.openwall.com/lists/oss-security/2010/05/18/12[WEB]
- http://www.openwall.com/lists/oss-security/2010/05/19/5[WEB]
- http://www.phpbb.com/community/viewtopic.php?f=14&p=9764445[WEB]