The message_options function in includes/ucp/ucp_pm_options.php in phpBB prior to 3.0.13 does not properly validate the form key, which allows remote malicious users to conduct CSRF attacks and change the full folder setting via unspecified vectors.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
phpbb phpbb |