Description
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.
Remediation
References
Related Vulnerabilities
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.15)
WordPress Plugin Lazy content Slider Cross-Site Request Forgery (3.4)
WordPress Plugin Contest Gallery-Photo Contest for WordPress SQL Injection (13.1.0.5)
WordPress Plugin WordPress Appointment Schedule Booking System Cross-Site Scripting (1.0)
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Cross-Site Scripting (2.3.0)