Server Side Request Forgery Vulnerability in phpBB by phpBB Group
CVE-2019-11767

5.8MEDIUM

Key Information:

Vendor

PHPbb

Status
Vendor
CVE Published:
5 May 2019

What is CVE-2019-11767?

A vulnerability in phpBB allows attackers to exploit the remote avatar upload feature to perform server side request forgery (SSRF). This can expose sensitive information by enabling the checking of file and service availability on the host's local network, potentially leading to unauthorized access to internal resources.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.