CVE-2017-1000419

HIGH

phpBB 3.2.0 - Server-Side Request Forgery via Remote Avatar Function

Title source: llm
STIX 2.1

Description

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0132
EPSS Percentile 67.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-918
Status published
Products (2)
phpbb/phpbb 3.2.0
phpbb/phpbb 3.2.0 - 3.2.1Packagist
Published Jan 02, 2018
Tracked Since Feb 18, 2026