CVE-2019-16108Code Injection in Phpbb

CWE-94Code Injection4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.3%
top 51.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 20
Latest updateMay 24

Description

phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Packagistphpbb/phpbb3.2.73.2.8
NVDphpbb/phpbb3.2.7

Patches

🔴Vulnerability Details

2
OSV
phpBB arbitrary CSS injection2022-05-24
GHSA
phpBB arbitrary CSS injection2022-05-24

🕵️Threat Intelligence

1
Wiz
CVE-2019-25685 Impact, Exploitability, and Mitigation Steps | Wiz