XenForo
cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*
- < 2.3.7
A vulnerability in XenForo versions prior to 2.3.7 allows for information disclosure through local account page caching on shared systems. In environments where multiple users share a browser or machine, cached account pages may inadvertently reveal sensitive user information to other local users.
Exploitation of this vulnerability could lead to unauthorized exposure of sensitive user information to other local users on the same system.
Users are advised to upgrade to XenForo version 2.3.7 or apply the available patch. Instructions for upgrading and downloading the patch are available on the XenForo community website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.