CyberRota Analysis
AI-GeneratedXenForo versions prior to 2.3.13 are vulnerable to a refresh token replay attack, where attackers can exploit the system's failure to invalidate refresh tokens after the corresponding access token expires. This allows for the unauthorized generation of new token pairs, enabling persistent access to the system. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token to generate additional independent token pairs, achieving persistent unauthorized access for the token's full lifetime.
Related CVEs
Other vulnerabilities affecting the same vendor(s)