CyberRota Analysis
AI-GeneratedXenForo versions prior to 2.3.13 are vulnerable due to a missing authorization flaw in the ACP cache-rebuild dispatcher, allowing limited administrators to execute unauthorized approval queue actions. This can lead to the approval of user registrations without proper permissions, enabling impersonation and potentially compromising the integrity of the moderation log. Organizations using affected versions should prioritize patching to mitigate risks associated with unauthorized user actions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying an arbitrary job class and actor user ID in the POST body. Attackers can invoke the approval queue job under any user identity to approve queued user registrations without holding the required approval-queue or moderator permissions, causing the moderation log to attribute actions to an impersonated account.
Related CVEs
Other vulnerabilities affecting the same vendor(s)