Description phpBB 3.2.8 allows a CSRF attack that can modify a group avatar. Remediation References CVE-2020-5501 Related Vulnerabilities Moodle Other Vulnerability (CVE-2007-1429) Jboss EAP Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2020-7238) Squid Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-9749) WordPress Plugin Custom Sidebars-Dynamic Widget Area Manager Cross-Site Scripting (2.1.0.1) XWiki Missing Authorization Vulnerability (CVE-2024-43401) Severity Medium Classification CVE-2020-5501 CWE-352 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Tags Missing Update Known Vulnerabilities