Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rwq-m5m5-h79g

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

EPSS

Процентиль: 67%
0.00539
Низкий

Связанные уязвимости

ubuntu
около 21 года назад

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

nvd
около 21 года назад

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

debian
около 21 года назад

phpBB 2.0.11, and possibly other versions, with remote avatars and ava ...

EPSS

Процентиль: 67%
0.00539
Низкий