Description
The message_options function in includes/ucp/ucp_pm_options.php in phpBB before 3.0.13 does not properly validate the form key, which allows remote attackers to conduct CSRF attacks and change the full folder setting via unspecified vectors.
Remediation
References
Related Vulnerabilities
Ruby Improper Input Validation Vulnerability (CVE-2009-4492)
Collabtive Improper Input Validation Vulnerability (CVE-2012-2670)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2001-1247)
WordPress Plugin WordPress Survey & Poll-Quiz, Survey and Poll PHP Object Injection (1.5.5)
PHP Improper Input Validation Vulnerability (CVE-2016-10397)