Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.0.12-1ubuntu0.1~esm1", "binary_name": "phpbb3" }, { "binary_version": "3.0.12-1ubuntu0.1~esm1", "binary_name": "phpbb3-l10n" } ] }
{ "ubuntu_priority": "medium" }