# Exploit Title: LayerBB 1.1.3 - Multiple CSRF # Date: 4/7/2019 # Author: 0xB9 # Twitter: @0xB9Sec # Contact: 0xB9[at]pm.me # Software Link: https://forum.layerbb.com/downloads.php?view=file&id=30 # Version: 1.1.3 # Tested on: Ubuntu 18.04 # CVE: CVE-2019-16531 1. Description: LayerBB is a free open-source forum software, multiple CSRF vulnerabilities were found such as editing user profiles and forums. 2. Proof of Concepts:

view_forum
create_thread
reply_thread
access_moderation
access_administration

This Usergroup is staff.

Do Not Change
Active
Disabled






Guest
User
Banned
Moderator
Administrator






Guest
User
Banned
Moderator
Administrator
Each Line is a new label. HTML enabled.












HTML tags will be converted into ascii codes. Hyperlinks are not supported!
HTML tags will be converted into ascii codes.
Use reCaptcha




Category Order Controls
test cat
test cat
First Category
First category on this forum!

Use ENTER to save catagory order

Node Order Controls
First Node
The first node on this forum
Sub-Forums:

Use ENTER to save catagory order




User
Banned
Moderator
Administrator






User
Banned
Moderator
Administrator
Each Line is a new label. HTML enabled.

view_forum
create_thread
reply_thread
access_moderation
access_administration

This Usergroup is staff.




Add an answer field











LayerBB Captcha


By clicking "Register", you agree to abide by the forum rules located here.
3. Solution: Update to 1.1.4