Impact
The flaw in XenForo's PayPal REST webhook handling allows an attacker to send a webhook with an unsupported auth_algo header, causing the signature verification logic to incorrectly return true when it cannot find a matching hash function. The caller interprets this as a valid signature and processes the payment event, enabling the attacker to fabricate payment notifications. This bypass leads to unauthorized payment processing or potential manipulation of payment data.
Affected Systems
This vulnerability affects XenForo forum software versions earlier than 2.3.13. The CNA indicates XenForo:XenForo as the affected product and no precise patch versions beyond 2.3.13. Thus any deployment of XenForo prior to 2.3.13 is susceptible.
Risk and Exploitability
The issue carries a CVSS score of 8.7, indicating high severity, and is not listed in CISA's KEV catalog. The EPSS score is unavailable, so the current exploitation probability is unknown, but the flaw permits unauthenticated attackers to create forged webhook requests, making it potentially exploitable over the network. The lack of authentication required for the exploit and the simplicity of the crafted request suggest a realistic risk for any exposed PayPal webhook endpoint. Attackers would typically target publicly reachable webhook URLs to inject malicious payment events.
OpenCVE Enrichment