PT-2023-21219 · Flarum · Flarum

Sycho9

·

Publicado

2023-03-10

·

Atualizado

2026-05-08

·

CVE-2023-27577

CVSS v3.1

6.6

Média

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions flarum versions prior to 1.7.0
Description The issue affects the LESS parser in flarum, allowing an attacker with a compromised admin account to read sensitive files on the server using path traversal techniques. This can be achieved by providing an absolute path to a sensitive file in the custom LESS setting. The scope of vulnerable files depends on the permissions given to the running flarum process. For example, an attacker could use the following code to read the contents of the /etc/passwd file on a Linux machine.
Recommendations To resolve the issue, upgrade to version 1.7.0. For users unable to upgrade, ensure admin accounts are secured with strong passwords and follow best practices for account security. Additionally, limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls at the operating system level.

Exploit

Correção

Path traversal

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-27577
GHSA-VHM8-WWRF-3GCW
GHSA-XJVC-PW2R-6878

Produtos afetados

Flarum