DEV Community

Cover image for Critical phpBB Vulnerabilities Allow Unauthenticated Account Takeover
BeyondMachines for BeyondMachines

Posted on • Originally published at beyondmachines.net

Critical phpBB Vulnerabilities Allow Unauthenticated Account Takeover

Summary

phpBB version 3.3.17 patches two vulnerabilities, PTT-2026-004 and PTT-2026-005, which allow unauthenticated attackers to hijack any user or administrator account.

Take Action:

There is no workaround for these flaws. Update your phpBB installation to version 3.3.17 immediately to prevent unauthenticated account takeovers.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)