XenForo Remote Code Execution via Authenticated Admin
43Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 8.6epss 0.7%
from disclosure to weapon
Published on NVDApr 1
VulnCheckMar 30
exploitation probability
0.7%top 51% of all CVEs
observed exploitation
yesVulnCheck
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
XenForo · XenForo