CVE-2015-3880

MEDIUM

phpBB <3.0.14, <3.1.4 - Open Redirect

Title source: llm
STIX 2.1

Description

Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing attacks via unspecified vectors.

References (6)

Core 6
Core References
Third Party Advisory x_refsource_confirm
https://wiki.phpbb.com/Release_Highlights/3.1.4
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/05/12/10
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74592
Third Party Advisory x_refsource_confirm
https://wiki.phpbb.com/Release_Highlights/3.0.14

Scores

CVSS v3 6.1
EPSS 0.0071
EPSS Percentile 72.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (7)
phpbb/phpbb 3.1.0 (14 CPE variants)
phpbb/phpbb 3.1.1
phpbb/phpbb 3.1.2 (2 CPE variants)
phpbb/phpbb 3.1.3 (3 CPE variants)
phpbb/phpbb 3.1.4 rc1 (2 CPE variants)
phpbb/phpbb < 3.0.14
phpbb/phpbb 0 - 3.0.14Packagist
Published Sep 19, 2017
Tracked Since Feb 18, 2026