Description phpBB 3.2.8 allows a CSRF attack that can modify a group avatar. Remediation References CVE-2020-5501 Related Vulnerabilities Microsoft SQL Server Other Vulnerability (CVE-2003-0231) OpenSSL Numeric Errors Vulnerability (CVE-2016-2106) WordPress 4.5.x Cross-Site Scripting Vulnerability (4.5 - 4.5.1) WordPress Plugin Responsive Slider-Image Slider-Slideshow for WordPress Multiple Vulnerabilities (2.7.5) WordPress 5.1.x Multiple Vulnerabilities (5.1 - 5.1.16) Severity Medium Classification CVE-2020-5501 CWE-352 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Tags Missing Update Known Vulnerabilities