VDB
Sign up
MEDIUM4.3

GHSA-cpqc-g4r8-6hxg

phpBB Cross-Site Request Forgery (CSRF)

Quick fix

GHSA-cpqc-g4r8-6hxg — phpbb/phpbb: upgrade to the fixed version with the command below.

composer require phpbb/phpbb:^3.2.9

Details

phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/phpbb/phpbb
Introduced in: 3.2.8Fixed in: 3.2.9
Fixcomposer require phpbb/phpbb:^3.2.9

References