vendor:
LayerBB
by:
0xB9
8.8
CVSS
HIGH
Multiple CSRF
352
CWE
Product Name: LayerBB
Affected Version From: 1.1.3
Affected Version To: 1.1.3
Patch Exists: YES
Related CWE: CVE-2019-16531
CPE: a:layerbb:layerbb:1.1.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2019
LayerBB 1.1.3 – Multiple CSRF
LayerBB is a free open-source forum software, multiple CSRF vulnerabilities were found such as editing user profiles and forums.
Mitigation:
Implementing CSRF protection, using tokens, and validating user input can help mitigate CSRF attacks.