PT-2023-7222 · Flarum+1 · Flarum+1

Adam Kues

·

Publicado

2023-08-16

·

Atualizado

2023-08-29

·

CVE-2023-40033

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:S/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Flarum versions prior to 1.8.0
Description The issue allows an attacker to conduct a Blind Server-Side Request Forgery (SSRF) attack or disclose any file on the server, even with a basic user account on any Flarum forum. This is due to the behavior of the intervention/image package, which attempts to interpret the supplied file contents as a URL, which then fetches its contents. An attacker can exploit this by uploading a file containing a URL and spoofing the MIME type, manipulating the application to execute unintended actions. This enables the attacker to perform SSRF attacks, disclose local file contents, or conduct a blind oracle attack.
Recommendations For versions prior to 1.8.0, upgrade to version 1.8.0 to resolve the issue. As a temporary workaround for the SSRF aspect of the vulnerability, consider disabling PHP's allow url fopen, which will prevent the fetching of external files via URLs.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08250
CVE-2023-40033
GHSA-67C6-Q4J4-HCCG

Produtos afetados

Flarum
Intervention/Image