Security Advisory

CVE-2019-13376

6.5
MEDIUM

Vulnerability Description

phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS
Published Date September 27, 2019
Official Source NIST NVD Advisory