-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| phpbb/phpbb | composer | >= 3.2.0, < 3.2.10 | 3.2.10 |
| phpbb/phpbb | composer | >= 3.3.0, < 3.3.1 | 3.3.1 |
The vulnerability stemmed from phpBB's use of the fast-image-size library (v1.0.*) to fetch remote image dimensions. The library's getImageSize method made uncontrolled HTTP requests to user-supplied URLs. Key functions identified: