PT-2023-18539 · Flarum · Flarum
Sycho9
·
Published
2023-01-10
·
Updated
2023-01-23
·
CVE-2023-22488
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Flarum versions prior to 1.6.3
Description
The issue allows an actor to read restricted or private content and bypass access checks by using the notifications feature. The notification-sending component does not verify if the subject of the notification is visible to the receiver, sending notifications through different channels. Although alerts do not leak data due to visibility checks, emails are still sent out. This enables bypassing restrictions on posts by subscribing to discussions when the Subscriptions extension is enabled. The attack can leak posts awaiting approval, posts in inaccessible tags, and posts restricted by third-party extensions.
Recommendations
To resolve the issue, upgrade to Flarum version 1.6.3 as soon as possible.
As a temporary workaround, consider disabling the Flarum Subscriptions extension or disabling email notifications altogether.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flarum