Description
phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.
Remediation
References
Related Vulnerabilities
WordPress Plugin Contact Form 7 Dynamic Text Extension Cross-Site Scripting (2.0.2.1)
Moodle Improper Access Control Vulnerability (CVE-2016-3729)
WordPress Plugin Custom 404 Pro Unspecified Vulnerability (3.7.0)
WordPress Plugin YAWPP (Yet Another WordPress Petition Plugin) SQL Injection (1.2)
IBM WebSEAL Improper Input Validation Vulnerability (CVE-2021-20496)