Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| phpbb/phpbb(Packagist) | 0 | 3.2.4 | N/A |
CVSS Metrics