PT-2026-29418 · Xenforo · Xenforo
Ticktackk
·
Published
2026-04-01
·
Updated
2026-04-01
·
CVE-2025-71282
CVSS v3.1
7.5
High
| AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open basedir restrictions. This allows an attacker to obtain information about the server's directory structure.
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xenforo