Impact
The flaw in the force‑agreement controller allows any ACP administrator to bypass the declared option permission and submit forced agreement forms. This results in the ability to update the global policy timestamp, forcing all users to re‑agree to privacy or terms documents. The vulnerability falls under CWE‑863 and effectively permits an authenticated administrator to perform privileged actions beyond their assigned rights, potentially undermining the platform’s contractual compliance mechanisms.
Affected Systems
XenForo versions prior to 2.3.13 are affected, including 2.3.12 and earlier releases of the XenForo core product. Users running a supported XenForo version of 2.3.13 or higher are not susceptible.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. Exploitability is limited to administrators with ACP access; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of widespread exploitation. Nevertheless, administrators must be aware that any ACP user can hijack the agreement process to force users to re‑accept policies, which may lead to audit or compliance violations.
OpenCVE Enrichment