GHSA-69q7-hww4-8pjq

Suggest an improvement
Source
https://github.com/advisories/GHSA-69q7-hww4-8pjq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-69q7-hww4-8pjq/GHSA-69q7-hww4-8pjq.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-69q7-hww4-8pjq
Aliases
Published
2022-05-24T17:06:46Z
Modified
2024-11-28T05:45:18.300971Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
phpBB allows CSRF
Details

phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.

Database specific
{
    "cwe_ids": [],
    "github_reviewed_at": "2023-07-13T17:08:08Z",
    "github_reviewed": true,
    "nvd_published_at": "2020-01-15T00:15:00Z",
    "severity": "MODERATE"
}
References

Affected packages

Packagist / phpbb/phpbb

Package

Name
phpbb/phpbb
Purl
pkg:composer/phpbb/phpbb

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.9

Affected versions

3.*

3.0.12-RC1
3.0.12-RC2
3.0.12-RC3
3.0.12
3.0.13-PL1
3.0.13-RC1
3.0.13
3.0.14-RC1
3.0.14
3.1.0-a1
3.1.0-a2
3.1.0-a3
3.1.0-b1
3.1.0-b2
3.1.0-b3
3.1.0-b4
3.1.0-RC1
3.1.0-RC2
3.1.0-RC3
3.1.0-RC4
3.1.0-RC5
3.1.0-RC6
3.1.0
3.1.1
3.1.2-RC1
3.1.2
3.1.3-RC1
3.1.3-RC2
3.1.3
3.1.4-RC1
3.1.4-RC2
3.1.4
3.1.5-RC1
3.1.5
3.1.6-RC1
3.1.6
3.1.7-RC1
3.1.7
3.1.7-pl1
3.1.8-RC1
3.1.8
3.1.9-RC1
3.1.9
3.1.10-RC1
3.1.10
3.1.11-RC1
3.1.11
3.1.12
3.2.0-a1
3.2.0-b2
3.2.0-RC1
3.2.0-RC2
3.2.0
3.2.1-RC1
3.2.1
3.2.2-RC1
3.2.2
3.2.3-RC1
3.2.3-RC2
3.2.3
3.2.4-RC1
3.2.4
3.2.5-RC1
3.2.5
3.2.6-RC1
3.2.6
3.2.7-RC1
3.2.7
3.2.8-RC1
3.2.8
3.2.9-RC1

Database specific

{
    "last_known_affected_version_range": "<= 3.2.8"
}