Impact
XenForo before version 2.3.13 has a flaw in the refresh‑token flow that fails to mark tokens as consumed once the parent access token expires. This allows an adversary to submit the same refresh token repeatedly and receive new token pairs, granting continued and independent authenticated access for the token’s full lifetime.
Affected Systems
The issue affects all XenForo deployments running any version earlier than 2.3.13. All users and administrators running these affected builds are at risk until a patch or newer version is applied.
Risk and Exploitability
With a CVSS score of 9.1 the vulnerability is considered Critical. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of exploit data does not reduce the severity. Based on the description, it is inferred that attackers must already possess a valid refresh token, which could be obtained through credential compromise, phishing, or other means. Based on the description, it is inferred that from there the attacker may repeatedly call the refresh endpoint over the network, subject to the tolerance of server resources. Based on the description, it is inferred that this remote exploitation path could be executed by a determined attacker without additional privilege escalation.
OpenCVE Enrichment