CVE-2018-17996 Information
Feb 14, 2021
cve
Description
LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php deleting a user via admin/members.php/delete_user/ and deleting content via mod/delete.php/.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Reference
http://packetstormsecurity.com/files/151694/LayerBB-1.1.2-Cross-Site-Request-Forgery.html https://github.com/AndyRixon/LayerBB/commits/master https://github.com/AndyRixon/LayerBB/issues/38 https://www.exploit-db.com/exploits/46379/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
6.5
Share on: