PT-2023-18539 · Flarum · Flarum

Sycho9

·

Published

2023-01-10

·

Updated

2023-01-23

·

CVE-2023-22488

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Flarum versions prior to 1.6.3
Description The issue allows an actor to read restricted or private content and bypass access checks by using the notifications feature. The notification-sending component does not verify if the subject of the notification is visible to the receiver, sending notifications through different channels. Although alerts do not leak data due to visibility checks, emails are still sent out. This enables bypassing restrictions on posts by subscribing to discussions when the Subscriptions extension is enabled. The attack can leak posts awaiting approval, posts in inaccessible tags, and posts restricted by third-party extensions.
Recommendations To resolve the issue, upgrade to Flarum version 1.6.3 as soon as possible. As a temporary workaround, consider disabling the Flarum Subscriptions extension or disabling email notifications altogether.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-22488
GHSA-8GCG-VWMW-RXJ4

Affected Products

Flarum