CVE-2008-7192

WoltLab Burning Board <3.0.1 - CSRF

Title source: llm

Description

Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentication of users for requests that delete private messages via the pmID parameter in a delete action in a PM page, a different vulnerability than CVE-2008-0472.

Exploits (1)

exploitdb WRITEUP VERIFIED
by StAkeR · textwebappsphp
https://www.exploit-db.com/exploits/8183

Scores

EPSS 0.0008
EPSS Percentile 23.2%

Classification

CWE
CWE-352
Status draft

Affected Products (1)

woltlab/burning_board

Timeline

Published Sep 09, 2009
Tracked Since Feb 18, 2026