Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.openwall.com/lists/oss-security/2011/10/10/4 | third party advisory mailing list |
https://packetstormsecurity.com/files/100103/UseBB-1.0.11-Cross-Site-Request-Forgery-Local-File-Inclusion.html | exploit vdb entry third party advisory |
https://www.immuniweb.com/advisory/HTB22913 | third party advisory exploit |