CVE-2017-1000419

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
02/01/2018
Last modified:
16/01/2018

Description

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpbb:phpbb:3.2.0:*:*:*:*:*:*:*