Vulnerability Description
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpbb | Phpbb | <= 3.1.7 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://github.com/phpbb/phpbb/commit/18abef716ecf42a35416444f3f84f5459d573789PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00036.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00006.htmlThird Party Advisory
- https://www.phpbb.com/community/viewtopic.php?t=2352606Vendor Advisory
- https://www.phpbb.com/support/documents.php?mode=changelog&version=3#v317Vendor Advisory
- https://github.com/phpbb/phpbb/commit/18abef716ecf42a35416444f3f84f5459d573789PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00036.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00006.htmlThird Party Advisory
- https://www.phpbb.com/community/viewtopic.php?t=2352606Vendor Advisory
- https://www.phpbb.com/support/documents.php?mode=changelog&version=3#v317Vendor Advisory
FAQ
What is CVE-2019-16993?
CVE-2019-16993 is a vulnerability with a CVSS score of 8.8 (HIGH). In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attack...
How severe is CVE-2019-16993?
CVE-2019-16993 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16993?
Check the references section above for vendor advisories and patch information. Affected products include: Phpbb Phpbb, Debian Debian Linux.