Impact
XenForo versions prior to 2.3.13 contain an unauthenticated information disclosure flaw, classified as CWE-639, that allows attackers to retrieve private unfurl records by supplying predictable auto‑increment primary key IDs to the unfurl endpoint. This manipulation bypasses all session, user, and visibility checks, enabling the extraction of rendered preview HTML, original URLs, and query strings from private conversations and other restricted content, thereby exposing confidential data.
Affected Systems
The affected product is XenForo; all installations running any version earlier than 2.3.13 are vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk, and while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the flaw remains exploitable by any unauthenticated user with network access to the unfurl endpoint. Attackers do not need additional credentials, making this vulnerability a straightforward disclosure vector once predictable IDs can be enumerated.
OpenCVE Enrichment