CVE-2019-13376
phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote A
phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS.
MEDIUM · CVSS 6.5
EPSS 0.00057
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0