Junglewise Threat Intelligence

CVE-2023-40033: Flarum vulnerable to LFI and Blind SSRF via Avatar upload

CVE-2023-40033 · Severity: low · CVSS 3.1 · Published 2023-08-16

Technologies: flarum/framework (Packagist), flarum/core (Packagist). Vendors: Packagist.

Executive brief

Flarum vulnerable to LFI and Blind SSRF via Avatar upload

Affected products

  • Packagist flarum/framework
  • Packagist flarum/core

Related threats