Impact
The vulnerability is a Server‑Side Request Forgery that allows attackers with administrator privileges or those who can add or save RSS feeds to make the application issue requests to internal network resources. This exposure can reveal the presence and port numbers of services running inside the host or disclose the server's original IP address. The weakness is identified as CWE‑918, which signifies that requests are made without proper validation or restrictions on the destination address.
Affected Systems
Xenforo 2.3.8 is affected. System administrators managing this version should verify whether the application is configured to allow RSS feed creation or administrative SSRF‑capable endpoints.
Risk and Exploitability
The CVSS score of 7.5 places the vulnerability in the high range, but its EPSS score is less than 1%, indicating a low current exploitation probability. The exploit requires access to an administrative account or the ability to add a RSS feed, so it is not a purely public remote attack. The vulnerability is not listed in the CISA KEV catalog, reflecting limited known exploitation in the wild.
OpenCVE Enrichment