Impact
The vulnerability is in the OAuth2 token endpoint of XenForo versions earlier than 2.3.13. By sending an authorization code with empty client_secret and code_verifier parameters, an unauthenticated attacker can bypass both client identity validation and PKCE verification. The attacker then receives a valid token pair and can use it to act as an authenticated user, compromising confidentiality and potentially enabling account takeover. This flaw is due to a logical error in PHP’s truthy evaluation and is classified as CWE‑697.
Affected Systems
All XenForo installations running a version prior to 2.3.13 are affected. The CVE payload does not specify a more granular version range or mention associated add‑ons. Only XenForo is listed as the affected vendor/product.
Risk and Exploitability
The CVSS score of 9.1 places this vulnerability in the critical range. The EPSS score is not available; it is not listed in the CISA KEV catalog. Attackers must first obtain a valid authorization code, which typically requires user interaction or access to the OAuth provider, but once they have it they can exchange it for tokens without any client authentication. The likely attack vector is a web‑based request to the OAuth2 token endpoint, and the vulnerability can be exploited remotely.
OpenCVE Enrichment