Researchers have identified critical security vulnerabilities in the popular forum software phpBB that allow attackers to take over user accounts without prior authentication. The vulnerabilities were present in the software for ten years and affect thousands of forums due to the standard configuration being vulnerable. PhpBB has released version 3.3.17 'Young Bertie' to address these issues, including four security flaws. One vulnerability allows attackers to obtain valid session tokens as any active user with a single HTTP request, enabling account takeover. Another issue relates to flaws in
Bias read (Center): The article reports on technical details of a software vulnerability and provides information about the release of a security update. It does not contain any political commentary, framing, or biased language. The content is purely informational and neutral.
Official sources cited
- organisation phpBB Team
- organisation Aikido Security Research Team
