CVE-2017-1000419: Phpbb
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.
Affected products
- Phpbb Phpbb: version 3.2.0 only
Published 2018-01-02. Last modified 2026-06-17.