Home
CRITICAL: 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
3.3.0 (semver)
affected
Description
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
Problem types
CWE-287 Improper Authentication - Generic
Product status
3.3.0 (semver)
References
www.phpbb.com/community/viewtopic.php?t=2672170