Impact
The vulnerability stems from XenForo’s failure to invalidate or mark OAuth2 authorization codes as consumed after the first token issuance. Consequently, attackers who obtain a previously used authorization code can submit it again and receive an additional token pair that grants access to the same user and scopes. This bypasses the single-use guarantee of the OAuth2 authorization code flow, potentially exposing any data or actions that the token scopes permit.
Affected Systems
The affected product is XenForo forum software, specifically all versions prior to 2.3.13. This includes the 2.2.x and 2.3.x series up to and including 2.3.12.
Risk and Exploitability
The CVSS score of 9.1 classifies this flaw as critical. Though an EPSS score is not available, the fact that it is not listed in the CISA KEV catalog does not diminish the risk. The vulnerability can be exploited remotely by submitting a known or intercepted authorization code through the OAuth2 endpoint, allowing an attacker to gain unauthorized access to the victim’s resources. Because the attack requires only the ability to reuse a code, and the code may be harvested via phishing or interception, the likelihood of exploitation remains significant for exposed installations.
OpenCVE Enrichment