VDB
Sign up
HIGH7.5

GHSA-jw8f-q84g-r3vm

phpBB vulnerable to sensitive information disclosure

Quick fix

GHSA-jw8f-q84g-r3vm — phpbb/phpbb: upgrade to the fixed version with the command below.

composer require phpbb/phpbb:^3.0.4

Details

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password prompts for a private message that quotes a post in a password-protected forum.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/phpbb/phpbb
Introduced in: 0Fixed in: 3.0.4
Fixcomposer require phpbb/phpbb:^3.0.4

References