QID 730676

Date Published: 2022-12-27

QID 730676: phpBB Server-Side Request Forgery (SSRF) Vulnerability

phpBB is an Internet forum package written in the PHP scripting language. Features of phpBB include support for multiple database engines, flat message structure, hierarchical sub-forums, topic split/merge/lock, user groups, multiple attachments per post, full-text search, plugins and various notification options.

CVE-2020-8226: Vulnerability exists in phpBB which allowed remote image dimensions check to be used to SSRF.

Affected Versions:
phpBB versions prior to 3.2.10
phpBB versions from 3.3.0 prior to 3.3.1
QID Detection Logic (Unauthenticated):
The detection uses Blind Elephant for fingerprinting phpBB versions.

Successful exploitation of this vulnerability may allow an attacker to use the image dimension check function to send requests on behalf of the server.

  • CVSS V3 rated as Medium - 5.8 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to phpBB 3.3.1 or later versions to remediate these vulnerabilities.

    CVEs related to QID 730676

    Software Advisories
    Advisory ID Software Component Link
    phpBB 3.2.10 URL Logo www.phpbb.com/community/viewtopic.php?f=14&t=2562631
    phpBB 3.3.1 URL Logo www.phpbb.com/community/viewtopic.php?f=14&t=2562636