CSRF Vulnerabilities in LayerBB 1.1.3: User Addition, User Deletion, and Content Deletion

CSRF Vulnerabilities in LayerBB 1.1.3: User Addition, User Deletion, and Content Deletion

CVE-2018-17996 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:P

LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.

Learn more about our User Device Pen Test.