The message_options function in includes/ucp/ucp_pm_options.php in phpBB before 3.0.13 does not properly validate the form key, which allows remote attackers to conduct CSRF attacks and change the full folder setting via unspecified vectors.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2015-02-10T17:00:00
Updated: 2024-08-06T04:40:18.701Z
Reserved: 2015-01-31T00:00:00
Link: CVE-2015-1432
Vulnrichment
No data.
NVD
Status : Modified
Published: 2015-02-10T17:59:01.290
Modified: 2024-11-21T02:25:24.973
Link: CVE-2015-1432
Redhat
No data.