XenForo
cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*
- < 2.3.5
An authorization vulnerability exists in XenForo versions prior to 2.3.5, allowing OAuth2 client applications to request unauthorized scopes. This could enable clients to access resources beyond their authorized limits. The issue affects all users of XenForo 2.3 who utilize OAuth2 clients.
Exploitation of this vulnerability could lead to unauthorized access to resources or functionalities, allowing OAuth2 client applications to operate beyond their intended permissions.
Users are advised to upgrade to XenForo version 2.3.5, which includes a critical security fix for this vulnerability. Instructions for upgrading are available on the XenForo website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.