CVE-2019-13376
27.09.2019, 13:15
phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS
Vendor | Product | Version |
---|---|---|
phpbb | phpbb | 3.2.7 |
𝑥
= Vulnerable software versions

Ubuntu Releases