LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
References
Link | Resource |
---|---|
https://github.com/0xB9/LayerBB-1.1.3-CSRF/blob/master/README.md | Exploit Third Party Advisory |
https://github.com/AndyRixon/LayerBB/pull/40 | Patch Third Party Advisory |
https://github.com/AndyRixon/LayerBB/compare/1.1.3...1.1.4 | Patch Third Party Advisory |
http://packetstormsecurity.com/files/154549/LayerBB-1.1.3-Cross-Site-Request-Forgery.html |
Configurations
Information
Published : 2019-09-19 19:16
Updated : 2019-09-20 10:15
NVD link : CVE-2019-16531
Mitre link : CVE-2019-16531
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
layerbb
- layerbb