CVE-2023-27577
Last modified
CVE-2023-27577 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. flarum is a forum software package for building communities. In versions prior to 1.7.0 an admin account which has already been compromised by an attacker may use a vulnerability in the `LESS` parser which can be exploited to read sensitive files on the server through the use of path traversal techniques. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
flarum is a forum software package for building communities. In versions prior to 1.7.0 an admin account which has already been compromised by an attacker may use a vulnerability in the `LESS` parser which can be exploited to read sensitive files on the server through the use of path traversal techniques. An attacker can achieve this by providing an absolute path to a sensitive file in the custom `LESS` setting, which the `LESS` parser will then read. For example, an attacker could use the following code to read the contents of the `/etc/passwd` file on a linux machine. The scope of what files are vulnerable will depend on the permissions given to the running flarum process. The vulnerability has been addressed in version `1.7`. Users should upgrade to this version to mitigate the vulnerability. Users unable to upgrade may mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and follow other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls at the operating system level.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Flarum | Flarum | < 1.7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-27577?
How severe is CVE-2023-27577?
How do I fix CVE-2023-27577?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-27570The eo_tags package before 1.4.19 for PrestaShop allows SQL …9.8
- CVE-2023-27571An issue was discovered in DG3450 Cable Gateway AR01.02.056.…5.3
- CVE-2023-27572An issue was discovered in CommScope Arris DG3450 Cable Gate…6.1
- CVE-2023-27573netbox-docker before 2.5.0 has a superuser account with defa…9.8
- CVE-2023-27574ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-tas…9.8
- CVE-2023-27576An issue was discovered in phpList before 3.6.14. Due to an …6.7
- CVE-2023-27578Galaxy is an open-source platform for data analysis. All sup…7.5
- CVE-2023-27579TensorFlow is an end-to-end open source platform for machine…7.5
- CVE-2023-2758A denial of service vulnerability exists in Contec CONPROSYS…5.3
- CVE-2023-27580CodeIgniter Shield provides authentication and authorization…5.9
- CVE-2023-27581github-slug-action is a GitHub Action to expose slug value o…8.8
- CVE-2023-27582maddy is a composable, all-in-one mail server. Starting with…9.8
Are you affected by CVE-2023-27577?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
