Session Hijacking Vulnerability in Flarum Forum Software by Flarum
CVE-2025-27794
6.8MEDIUM
What is CVE-2025-27794?
Flarum forum software is susceptible to a session hijacking vulnerability which affects versions prior to 1.8.10. This issue arises when an attacker controls an authoritative subdomain that can set cookies for the parent domain. If session tokens are not rotated after authentication, an attacker could exploit this by replacing session tokens in sibling subdomains. To successfully execute this attack, the attacker must possess control over any subdomain of the parent domain, and the parent domain must not appear on the Public Suffix List. Although the theoretical reproduction of the issue seems feasible, current browser security measures limit actual exploitability. The vulnerability has been addressed in version 1.8.10.
Affected Version(s)
framework < 1.8.10
