HIGH7.2
GHSA-h3mr-q96r-37v4
phpBB Remote Code Execution
Quick fix
GHSA-h3mr-q96r-37v4 — phpbb/phpbb: upgrade to the fixed version with the command below.
composer require phpbb/phpbb:^3.2.4Details
Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-19274[ADVISORY]
- https://blog.ripstech.com/2018/phpbb3-phar-deserialization-to-remote-code-execution[WEB]
- https://github.com/phpbb/phpbb-app[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2018/11/msg00029.html[WEB]
- https://www.phpbb.com/community/viewtopic.php?f=14&t=2492206[WEB]