CVE-2018-17996 describes a Cross-Site Request Forgery (CSRF) vulnerability in LayerBB versions prior to 1.1.3. This flaw allows an attacker to trick an authenticated administrator into performing actions such as adding a new user, deleting an existing user, or deleting content without their explicit consent. With a CVSS score of 6.5 (Medium), the vulnerability requires user interaction (UI:R) but can be exploited remotely (AV:N) with low attack complexity (AC:L), potentially leading to high integrity impact (I:H) by unauthorized modifications. While not actively exploited in the wild and not listed in CISA's KEV catalog, a public exploit (EDB-46379) exists for adding an administrator, indicating its exploitability. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.2CPE matchmatch criteria | cpe:2.3:a:layerbb:layerbb:1.1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.