PT-2025-11049 · Flarum · Flarum

Imorland

·

Publicado

2025-03-12

·

Atualizado

2025-04-02

·

CVE-2025-27794

CVSS v3.1

6.8

Média

VetorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Flarum versions prior to 1.8.10
Description: A session hijacking issue exists when an attacker-controlled authoritative subdomain under a parent domain sets cookies scoped to the parent domain. This allows session token replacement for applications hosted on sibling subdomains if session tokens aren't rotated post-authentication. Key constraints include the attacker controlling any subdomain under the parent domain and the parent domain not being on the Public Suffix List. The issue can theoretically be reproduced using browser dev tools but is not exploitable due to browser security measures.
Recommendations: For versions prior to 1.8.10, update to version 1.8.10 to resolve the issue. As a temporary workaround, consider implementing session token rotation after authentication to minimize the risk of exploitation. Additionally, restrict cookies to explicit subdomains and consider adding the parent domain to the Public Suffix List to prevent such attacks.

Exploit

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-27794
GHSA-HG9J-64WP-M9PX

Produtos afetados

Flarum