Server-Side Request Forgery in XenForo PayPal Webhook Handler
CVE-2026-73315
7.7HIGH
What is CVE-2026-73315?
XenForo prior to version 2.3.13 is susceptible to a server-side request forgery vulnerability in its PayPal REST webhook handler. This vulnerability allows unauthenticated attackers to manipulate the server into making outbound HTTP requests to arbitrary destinations. By providing a specially crafted certificate URL within the webhook headers, which bypasses necessary scheme and hostname validations, attackers can exploit the vulnerability. Such attacks could potentially access sensitive internal network resources, including cloud instance metadata services, leading to the exposure of IAM credentials and facilitating further exploitation of internal services.
Affected Version(s)
XenForo 0 < 2.3.13
