CVE-2019-11767

MEDIUM

phpBB < 3.2.6 - Server-Side Request Forgery via Remote Avatar Upload

Title source: llm
STIX 2.1

Description

Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host through the remote avatar upload function.

References (1)

Core 1
Core References

Scores

CVSS v3 5.8
EPSS 0.0118
EPSS Percentile 63.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Details

CWE
CWE-918
Status published
Products (2)
phpbb/phpbb < 3.2.6
phpbb/phpbb 0 - 3.2.6Packagist
Published May 05, 2019
Tracked Since Feb 18, 2026