CVE-2024-21641 is an open redirect vulnerability affecting Flarum discussion platform software prior to version 1.8.5. It allows an attacker to redirect users from a trusted Flarum domain to any arbitrary link via the /logout route. This vulnerability has a CVSS score of 4.7 (Medium), indicating a low impact on integrity (I:L) and no impact on confidentiality or availability, with a network attack vector (AV:N) and low attack complexity (AC:L). The primary risk is phishing or driving traffic to malicious sites using the trusted domain. There is no evidence of active exploitation, and no Metasploit or ExploitDB modules are available. However, Nuclei templates exist for detection, and despite a high FAUCET Risk Score, there is currently no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.5CPE matchmatch criteria | cpe:2.3:a:flarum:flarum:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.