CVE-2003-1215SQL Injection in Group Phpbb

2 documents2 sources
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 80.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 29
Latest updateApr 29

Description

SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages1 packages

NVDphpbb_group/phpbb19 versions+18

Patches

🔴Vulnerability Details

1
GHSA
GHSA-jfjg-c5hf-9wc8: SQL injection vulnerability in groupcp2022-04-29