phpBB Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2019-13376 - Vulnerability Database

phpBB Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2019-13376

Medium
Reference: CVE-2019-13376
Title: phpBB Cross-Site Request Forgery (CSRF) Vulnerability
Overview:

phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS