CVE-2025-27794

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Mar 12, 2025
Updated: Apr 2, 2025
CWE ID 74

Summary

CVE-2025-27794 is a session hijacking vulnerability affecting Flarum, an open-source forum software. This issue arises when an attacker controls an authoritative subdomain under a parent domain and sets cookies scoped to the parent domain. Applications hosted on sibling subdomains are susceptible to session token replacement if session tokens aren't rotated post-authentication. The attacker must control any subdomain under the parent domain, and the parent domain should not be on the Public Suffix List. Although theoretically exploitable using browser dev tools, the vulnerability may not be practically exploited due to browser security measures. Version 1.8.10 of Flarum includes a patch to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share