« Volver al listado

CVE-2015-1432

Estado: ModificadaMedia (6.8)—

The message_options function in includes/ucp/ucp_pm_options.php in phpBB before 3.0.13 does not properly validate the form key, which allows remote attackers to conduct CSRF attacks and change the full folder setting via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-1432",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-02-10T17:59:01.290",
  "references": [
    {
      "url": "http://seclists.org/oss-sec/2015/q1/373",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/72399",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/100671",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/phpbb/phpbb/commit/23069a13e203985ab124d1139e8de74b12778449",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/phpbb/phpbb/pull/3311",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://security.gentoo.org/glsa/201701-25",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://tracker.phpbb.com/browse/PHPBB3-13526",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://wiki.phpbb.com/Release_Highlights/3.0.13",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://seclists.org/oss-sec/2015/q1/373",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/72399",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/100671",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/phpbb/phpbb/commit/23069a13e203985ab124d1139e8de74b12778449",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/phpbb/phpbb/pull/3311",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/201701-25",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://tracker.phpbb.com/browse/PHPBB3-13526",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.phpbb.com/Release_Highlights/3.0.13",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The message_options function in includes/ucp/ucp_pm_options.php in phpBB before 3.0.13 does not properly validate the form key, which allows remote attackers to conduct CSRF attacks and change the full folder setting via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "La función message_options en includes/ucp/ucp_pm_options.php en phpBB anterior a 3.0.13 no valida correctamente la clave del formulario, lo que permite a atacantes remotos realizar ataques de CSRF y cambiar la configuración de ficheros completos a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:22:25.067",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:phpbb:phpbb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFE6F91C-2F7A-4905-AEB4-EDC03131D412",
              "versionEndIncluding": "3.0.12"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}