Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

[URGENT] Workaround to prevent authentication bypass in phpBB 3.1.0 - 3.3.16

Дата публикации: 13-06-2026 06:15:14

Greetings everyone,
As mentioned in the release announcement of phpBB 3.3.17, a security issue noticed in phpBB versions 3.3.16 and prior could have been used to hijack user accounts. Due to the criticality of this issue, we urge admins to update to 3.3.17 as soon as possible or disable access to their forums until they manage to do so.
If you are not able to update to 3.3.17 yet and do not use Apache or LDAP authentication on your board, you can remove the following two files as a temporary workaround ({root} used as indicator of the forum root directory):
{root}/phpbb/auth/provider/apache.php
{root}/phpbb/auth/provider/ldap.php
In addition to that, we recommend that you disable OAuth in the ACP until you find ample time to update.
Note: This workaround will result in an error when visiting the authentication provider page in the ACP. You can add the files back when updating to 3.3.17 and the error should then be resolved.
- The phpBB Team

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1PHP Type Juggling: как нестрогое сравнение превращается в обход аутентификации08.122-07-2026
2Предложение на Форум2327-06-2026
3The Fragile Lock: Novel Bypasses For SAML Authentication0810-12-2025
4Looper not showing author?0312-07-2026
5Announcing FusionAuth 1.63 - The Proof Pangolin012.6726-02-2026
6milpa/auth (v0.3.0)010.9428-07-2026
7BuddyPress 14.5.0, 12.7.0 & 11.6.0 Maintenance and Security Releases030.5808-07-2026
8Mike Witt replied to the topic Unauthenticated Arbitrary Shortcode Execution Security Vulnerability in the forum Requests & Feedback0530-01-2026
9litestar-auth - auth backend для litestar026.6710-05-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 8.59. Источник: www.phpbb.com.