216.73.216.197

CVE-2026-48613

· Published 12/06/2026 04:17 · Modified 12/06/2026 16:15

Labels: CVE-2026-48613 2026-06-12CVE-2026-48613CWE-89[email protected]

Essential information

Published
12/06/2026 04:17
Modified
12/06/2026 16:15
Author
Creator
CVSS
5.9 MEDIUM (v3.0)
CISA KEV
No
CWE
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L

CVSS metrics

Description

SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution of arbitrary SQL queries. Only applies to phpBB forums that had been updated from versions prior to phpBB 3.3.8 and have not been updated to 3.3.11 or newer yet.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
phpbb / phpbb cpe:2.3:a:phpbb:phpbb:<3.3.8:*:*:*:*:*:*
phpbb / phpbb cpe:2.3:a:phpbb:phpbb:3.3.8:*:*:*:*:*:*
phpbb / phpbb cpe:2.3:a:phpbb:phpbb:<3.3.11:*:*:*:*:*:*

References