ZeroHour

CVE-2019-13376

PoC ×2
CVSS 3.1
6.5 medium
EPSS
<1%p50
Published
()
Modified
Description

phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS

Vendors
phpbb
Products
phpbb
Weakness
CWE-79, CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.