CVE-2019-13376
27.09.2019, 13:15
phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS
| Vendor | Product | Version |
|---|---|---|
| phpbb | phpbb | 3.2.7 |
𝑥
= Vulnerable software versions
Ubuntu Releases