MEDIUM6.1
GHSA-hwq7-cvp8-6hm3
phpBB Open Redirect
Quick fix
GHSA-hwq7-cvp8-6hm3 — phpbb/phpbb: upgrade to the fixed version with the command below.
composer require phpbb/phpbb:^3.0.14Details
Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-3880[ADVISORY]
- https://github.com/phpbb/phpbb/commit/1a3350619f428d9d69d196c52128727e27ef2f04[WEB]
- https://github.com/phpbb/phpbb/commit/c1702b8e19a69c98ef049abb4e14157e3e208ed4[WEB]
- https://github.com/phpbb/phpbb[PACKAGE]
- https://web.archive.org/web/20170520103544/http://www.securityfocus.com/bid/74592[WEB]
- https://wiki.phpbb.com/Release_Highlights/3.0.14[WEB]
- https://wiki.phpbb.com/Release_Highlights/3.1.4[WEB]
- https://www.phpbb.com/community/viewtopic.php?f=14&t=2313941[WEB]
- http://www.openwall.com/lists/oss-security/2015/05/12/10[WEB]