PT-2025-11049 · Flarum · Flarum
Imorland
·
Published
2025-03-12
·
Updated
2025-04-02
·
CVE-2025-27794
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Flarum versions prior to 1.8.10
Description:
A session hijacking issue exists when an attacker-controlled authoritative subdomain under a parent domain sets cookies scoped to the parent domain. This allows session token replacement for applications hosted on sibling subdomains if session tokens aren't rotated post-authentication. Key constraints include the attacker controlling any subdomain under the parent domain and the parent domain not being on the Public Suffix List. The issue can theoretically be reproduced using browser dev tools but is not exploitable due to browser security measures.
Recommendations:
For versions prior to 1.8.10, update to version 1.8.10 to resolve the issue. As a temporary workaround, consider implementing session token rotation after authentication to minimize the risk of exploitation. Additionally, restrict cookies to explicit subdomains and consider adding the parent domain to the Public Suffix List to prevent such attacks.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flarum