Junglewise Threat Intelligence

CVE-2026-48613: phpBB SQL injection in profile field migration

CVE-2026-48613 · Severity: medium · CVSS 5.9 · Published 2026-06-12

Technologies: Phpbb. Vendors: Phpbb.

Executive brief

phpBB, a popular open-source forum software, contains a security flaw in how it handles user profile data during system updates. An attacker could potentially exploit this to run unauthorized database commands, which may lead to the theft of sensitive user information or disruption of the forum's operations. This issue specifically affects forums that were upgraded from older versions but have not yet been updated to the latest security release.

Technical details

A SQL injection vulnerability exists in the phpBB profile field migration component (CWE-89). The root cause is the improper neutralization of user-supplied profile field data during the migration process. An attacker with low-level privileges (PR:L) could exploit this over the network, though it requires high complexity (AC:H) and potentially user interaction (UI:R). Successful exploitation allows the execution of arbitrary SQL queries, potentially leading to unauthorized data access or modification. The vulnerability specifically impacts forums updated from versions prior to 3.3.8 that have not yet reached version 3.3.11.

Affected products

  • phpBB phpBB >= 3.3.8, < 3.3.11

Timeline

  • 2026-06-12: disclosed: CVE published to NVD dataset
  • 2026-06-12: advisory: Official phpBB community announcement published

References