Flarum.Core.XSS

description-logoDescription

This indicates an attack attempt to exploit a Cross-Site Scripting Vulnerability in Flarum Flarum Core.
The vulnerability is due to incorrect sanitization of HTML Markup in Flarum's translation library resulting in both Stored and Reflected Cross-Site Scripting vectors. A remote attacker could exploit this vulnerability by sending a crafted request to the target system or enticing a user to click a crafted URL. A successful attack may result in execution of script code in the security context of the browser of any user visiting the affected pages.

affected-products-logoAffected Products

Flarum Flarum Core 1.0.0
Flarum Flarum Core 1.0.1

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary script code in the context of the affected application.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://github.com/flarum/core/security/advisories/GHSA-5qjq-69w6-fg57

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-09-17 18.160 Default_action:pass:drop
2021-09-08 18.153