CyberRota Analysis
AI-GeneratedXenForo versions prior to 2.3.13 are vulnerable due to a missing authorization flaw in the force-agreement controller, enabling any ACP administrator to access and submit force-agreement forms without proper permissions. This vulnerability allows unauthorized updates to the global policy timestamp, potentially forcing all users to re-accept privacy policies or terms of service. Organizations using XenForo should prioritize this issue to mitigate the risk of unauthorized policy enforcement and ensure compliance.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can bypass the option permission declared in the navigation configuration to update the global policy last-updated timestamp, forcing all users to re-agree to the privacy policy or terms of service.
Related CVEs
Other vulnerabilities affecting the same vendor(s)