Description
phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header.
Remediation
References
Related Vulnerabilities
Grafana Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-27962)
Oracle Database Server CVE-2012-1746 Vulnerability (CVE-2012-1746)
Artifactory CVE-2023-42508 Vulnerability (CVE-2023-42508)
Ampache Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2008-3929)