MansionNET has a forum now! :)
https://forum.inthemansion.com is a self-hosted phpBB board for the community around our IRC network, search, radio and git. No ads, no tracking, no third-party CDNs.
Just rooms in a house: a Library, a Garage for self-hosting talk, an Observatory, a Basement for the off-topic stuff, and many more :)
Open for new registrations, so hope to see you here!
🚨 ACHTUNG!
Falls ihr ein #phpBB-Forum betreibt: Ihr wollt GENAU JETZT GANZ DRINGEND updaten.
Tl;dr: Auth-bypass mit der Option, beliebige (auch admin!)-Konten zu übernehmen.
#Discord alternatives #List #OpenSource :
#PHPBB, #Discourse, #Flarum, #Prosody, #Deltachat, #Zulip, etc.
A shocking 10-year-old authentication bypass bug in phpBB has been patched, revealing how easily attackers could gain full admin control over thousands of forums. Discovered by Aikido researchers, this "trivial" flaw underscores the immense security risks of legacy code and the critical importance of prompt patching. Update to phpBB 3.3.17 without delay.
🤖 This post was AI-generated.
Apparently there is a critical #phpBB vulnerability (CVE-2026-48611) that allows anyone to hijack user accounts on any forum with a vulnerable version that has mostly flown under the radar. Someone on a forum I frequent managed to log into the admin account to demonstrate it.
The fix seems to be to update to phpBB 3.3.17 (or tell the admin of a forum you frequent to do so), ASAP:
phpBB Fixes Decade-Old Auth Bypass Bug
A major vulnerability in phpBB has been uncovered, allowing attackers to bypass authentication and log in as any user, including administrators, with ease and no special knowledge required. This decade-old bug, exploitable in default configurations, has been patched - but only after researchers took steps to privately disclose the issue to prevent…
https://osintsights.com/phpbb-fixes-decade-old-auth-bypass-bug?utm_source=mastodon&utm_medium=social
#AuthBypass #Phpbb #VulnerabilityDisclosure #Hackerone #ApplicationSecurity