Impact
The vulnerability exists in the OAuth2 token endpoint of XenForo implementations versioned before 2.3.13. An attacker who can control any of the allowlisted redirect URIs can exploit a flaw that ignores the binding between that URI and the authorization request, substituting a different allowlisted URI at the token‑exchange step. This allows the attacker to redeem an intercepted authorization code and receive the client’s access token, granting unauthorized access to protected resources.
Affected Systems
All installations of XenForo released prior to version 2.3.13 are affected. System owners using any XenForo version below 2.3.13 should review OAuth2 redirect URI configurations and plan an upgrade.
Risk and Exploitability
The CVSS base score of 8.2 classifies the flaw as high severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, yet the exploitation path remains viable for a remote attacker who can coordinate a legitimate redirect URI. Attackers would need only to intercept the authorization flow or supply a pre‑existing allowlisted URI and then exchange the authorization code with the mismatched redirect, a straightforward operation that can be performed over the public internet. Consequently, the risk of exploitation is significant for exposed instances that retain weak redirect‑URI handling.
OpenCVE Enrichment