phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| phpbb/phpbb(Packagist) | 0 | 3.2.8 | N/A |
CVSS Metrics