phpBB是phpbb团队开源的一套基于PHP的Web论坛软件。 phpBB 3.3.0至3.3.16及之前版本存在授权问题漏洞,该漏洞源于OAuth实现中的身份验证检查不当,可能导致账户劫持,导致默认安装中的未授权访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | phpBB before 3.3.17 contains an authentication bypass vulnerability in the login-link feature. By setting the auth_provider query parameter to "apache", an unauthenticated attacker can bypass password verification and log in as any user, including administrators. The Apache auth provider trusts the Basic authentication header username without password verification, as it assumes Apache handles authentication upstream. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-48611.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-47366 | phpBB 权限许可和访问控制问题漏洞 | |
| CVE-2026-48613 | phpBB SQL注入漏洞 | |
| CVE-2026-48612 | phpBB 跨站请求伪造漏洞 |
No comments yet