CVE-2023-22487 is a data leakage vulnerability affecting Flarum forum software versions prior to 1.6.3, specifically within the flarum/mentions extension. An authenticated attacker with post creation privileges can exploit this flaw to leak the full JSON:API payload of any mentioned post, including content, date, and attributes, even if they lack direct access to that post. This medium-severity vulnerability (CVSS 4.3) allows for unauthorized disclosure of sensitive forum data, including posts awaiting approval or those in restricted tags. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.3CPE matchmatch criteria | cpe:2.3:a:flarum:flarum:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.