Session Hijacking Vulnerability in Flarum Forum Software by Flarum
CVE-2025-27794

6.8MEDIUM

Key Information:

Vendor

Flarum

Status
Vendor
CVE Published:
12 March 2025

What is CVE-2025-27794?

Flarum forum software is susceptible to a session hijacking vulnerability which affects versions prior to 1.8.10. This issue arises when an attacker controls an authoritative subdomain that can set cookies for the parent domain. If session tokens are not rotated after authentication, an attacker could exploit this by replacing session tokens in sibling subdomains. To successfully execute this attack, the attacker must possess control over any subdomain of the parent domain, and the parent domain must not appear on the Public Suffix List. Although the theoretical reproduction of the issue seems feasible, current browser security measures limit actual exploitability. The vulnerability has been addressed in version 1.8.10.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

framework < 1.8.10

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.