CVE-2011-5090: Grboard
Medium severity, CVSS 6.4. EPSS: 1.3% chance of exploitation in the next 30 days.
GR Board (aka grboard) 1.8.6.5 Community Edition does not require authentication for certain database actions, which allows remote attackers to modify or delete data via a request to (1) mod_rewrite.php, (2) comment_write_ok.php, (3) poll/index.php, (4) update/index.php, (5) trackback.php, or (6) an arbitrary poll.php script under theme/.
Affected products
- Grboard Grboard: version 1.8.6.5 only
Published 2012-05-24. Last modified 2026-06-16.