Email Token Invalidation Flaw in Flarum by Flarum
CVE-2019-11514
7.5HIGH
What is CVE-2019-11514?
A flaw in the User/Command/ConfirmEmailHandler.php component of Flarum versions prior to 0.1.0-beta.8 leads to improper handling of user email token invalidation. This vulnerability can potentially allow unauthorized users to exploit shortcomings in email token management, posing risks to user account security. Developers utilizing affected versions are advised to update to the latest release to mitigate these risks.
