CVE 7.1 HIGH

CVE-2026-48613_CVE-2026-48613

7.1 / 10
HIGH
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L/CR:H/IR:H/AR:H

Description

SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution of arbitrary SQL queries. Only applies to phpBB forums that had been updated from versions prior to phpBB 3.3.8 and have not been updated to 3.3.11 or newer yet.

Basic Information

ID CVE-2026-48613
Source hackerone
Published Jun 12, 2026 at 02:27

Affected Product

Vendor phpBB
Product phpBB
Version 3.3.8
Affected Versions phpBB phpBB 3.3.8

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.