phpBB forum fixes auth bypass bug lurking for a decade
ID: 229a33dd-d87b-5d72-8c67-ce08ca1db4e0
STIX ID: report--229a33dd-d87b-5d72-8c67-ce08ca1db4e0
Feed Name: Bleeping Computer
A decade-old authentication bypass in phpBB (affecting 3.x up to 3.3.16 and 4.0.0-a2) allows trivial account takeover — including administrator accounts — via a single HTTP request; phpBB released a fix in 3.3.17 for the 3.x branch while 4.x remains without a safe release. Exploitation requires no special configuration, could enable full forum administration (view private messages, modify accounts/content), and researchers temporarily withheld technical details to allow admins to patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
