Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.phpbb.com/community/viewforum.php?f=14 | release notes vendor advisory |
https://www.phpbb.com/community/viewtopic.php?t=2523271 | release notes vendor advisory |