CyberRota Analysis
AI-GeneratedXenForo versions prior to 2.3.13 are vulnerable due to an authorization flaw in the OAuth2 token endpoint, allowing attackers to exploit allowlisted redirect URIs to bypass redirect URI binding. This vulnerability enables the interception of authorization codes, potentially leading to the theft of OAuth2 tokens. Organizations using affected versions of XenForo should prioritize patching to mitigate the risk of unauthorized access to sensitive user data.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows.
Related CVEs
Other vulnerabilities affecting the same vendor(s)