CVE-2026-48613 - CERT CVE
ID CVE-2026-48613
Sažetak SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution of arbitrary SQL queries. Only applies to phpBB forums that had been updated from versions prior to phpBB 3.3.8 and have not been updated to 3.3.11 or newer yet.
Reference
CVSS
Base: 5.9
Impact: 4.7
Exploitability:1.2
Pristup
VektorSloženostAutentikacija
NETWORK HIGH LOW
Impact
PovjerljivostCjelovitostDostupnost
HIGH LOW LOW
CVSS vektor CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L
Zadnje važnije ažuriranje 12-06-2026 - 16:15
Objavljeno 12-06-2026 - 04:17