Impact
XenForo versions prior to 2.3.13 contain a cross‑site scripting flaw in the dynamic redirect handler that allows an attacker who does not need to be authenticated to craft a malicious javascript: URI. By embedding the board hostname in the URI authority and inserting percent‑encoded newlines, the attacker bypasses server‑side host validation checks and causes any authenticated user who follows the crafted link to execute attacker‑supplied JavaScript within the board’s origin context. This can expose session cookies, allow session hijacking, or enable arbitrary actions performed by the user’s browser.
Affected Systems
Affected systems are XenForo installations running any release earlier than 2.3.13.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity vulnerability with a relatively limited scope that requires a user to click a crafted link. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet reported. Nevertheless, because the flaw permits arbitrary JavaScript execution in the context of a valid user session, it presents a significant threat if an attacker can deliver a link to users. The attack vector is remote, unauthenticated, and depends on user interaction.
OpenCVE Enrichment