PT-2026-29418 · Xenforo · Xenforo
Ticktackk
·
Published
2026-04-01
·
Updated
2026-04-01
·
CVE-2025-71282
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
XenForo versions prior to 2.3.7
Description
XenForo versions prior to 2.3.7 disclose filesystem paths through exception messages triggered by
open basedir restrictions. This allows an attacker to obtain information about the server's directory structure.Recommendations
Update to version 2.3.7 or later.
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xenforo