CVE-2023-40033 is a high-severity vulnerability affecting Flarum open-source forum software, allowing authenticated attackers to perform Blind Server-Side Request Forgery (SSRF) or disclose local files. This is due to the 'intervention/image' package misinterpreting uploaded file contents as a URL, leading to unintended actions. With a CVSS score of 7.1, the vulnerability has a low attack complexity and can result in high confidentiality impact. While there are no known public exploits or Metasploit modules, the vulnerability has garnered significant community discussion and media coverage, indicating awareness among researchers. Flarum version 1.8.0 patches this issue, and disabling PHP's allow_url_fopen is a temporary workaround for the SSRF aspect.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.0CPE matchmatch criteria | cpe:2.3:a:flarum:flarum:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.