VDB
Sign up
HIGH7.2

GHSA-h3mr-q96r-37v4

phpBB Remote Code Execution

Quick fix

GHSA-h3mr-q96r-37v4 — phpbb/phpbb: upgrade to the fixed version with the command below.

composer require phpbb/phpbb:^3.2.4

Details

Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/phpbb/phpbb
Introduced in: 0Fixed in: 3.2.4
Fixcomposer require phpbb/phpbb:^3.2.4

References