Settings

Theme

Critical auth bypass vulnerability in phpBB

aikido.dev

2 points by Tiberium 16 days ago · 1 comment

Reader

TiberiumOP 16 days ago

I tested it myself, seems to reproduce on: 3.1.0-a1 to 3.3.16, 4.0.0-a1 / 4.0.0-a2. Fixed in 3.3.17 and in master.

Gives you auth + access to Moderation Control Panel (if the user is a moderator/admin). Does not give access to the Admin Control Panel though.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection