VDB
Sign up
HIGH8.8

GHSA-vj3x-vfm4-hvxc

phpBB Cross-Site Request Forgery (CSRF)

Quick fix

GHSA-vj3x-vfm4-hvxc — phpbb/phpbb: upgrade to the fixed version with the command below.

composer require phpbb/phpbb:^3.1.7-PL1

Details

In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/phpbb/phpbb
Introduced in: 0Fixed in: 3.1.7-PL1
Fixcomposer require phpbb/phpbb:^3.1.7-PL1

References