phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.
{ "severity": "Medium", "cpes": [ "cpe:2.3:a:phpbb:phpbb:3.2.8:*:*:*:*:*:*:*" ] }
"https://github.com/bitnami/vulndb/tree/main/data/phpbb/BIT-phpbb-2020-5502.json"