MEDIUM
phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header
Published Sep 1, 2009
6.8
MEDIUMCVSS 2.0
EPSS 1.05%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.