ZeroHour

CVE-2019-11767

CVSS 3.0
5.8 medium
EPSS
1%p66
Published
()
Modified
Description

Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host through the remote avatar upload function.

Vendors
phpbb
Products
phpbb
Weakness
CWE-918
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.