Impact
The weakness is a path traversal flaw in XenForo’s style archive importer on Windows. By uploading a ZIP file that contains filenames with backslash separators, an authenticated user who has style‑edit permissions but is not a super administrator can cause the importer to extract files outside the expected directory. The backslashes bypass the forward‑slash check, allowing arbitrary file creation or overwrite wherever the web server can write. If the attacker places executable code in the public web root or another writable location, the web server will run it under its own account, granting the attacker persistent control over the application.
Affected Systems
Any XenForo installation running a Windows operating system and having a version earlier than 2.3.13 is vulnerable. The issue is tied to the native style‑archive import feature, independent of add‑ons, and does not affect Linux or macOS deployments.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is considered high severity, indicating a serious threat to confidentiality, integrity, and availability. No EPSS score is available, but the requirement of user authentication with style‑permissions means that an attacker must first compromise or obtain credentials for a regular user. Once authenticated, the attacker can craft the malicious ZIP archive and trigger the importer; no special network exposure is needed beyond normal web service access. The vulnerability is not listed in the CISA KEV catalog and no official exploits are publicly documented, yet the path traversal itself directly enables arbitrary file writes that lead to code execution.
OpenCVE Enrichment