Executive brief
YetAnotherForum.NET (YAF.NET) is an open-source forum software used to host community discussions. A security flaw allows unauthenticated attackers to inject malicious scripts into the forum's administrative logs by sending a specially crafted web request. If an administrator views these logs, the script executes in their browser, potentially allowing the attacker to take full control of the forum, steal user data, or create new administrative accounts.
Technical details
A stored (second-order) Cross-Site Scripting (XSS) vulnerability exists in YAF.NET's database logger (DbLogger.cs). The application captures the 'User-Agent' HTTP header from incoming requests and stores it as a JSON object in the EventLog table when an exception occurs. The administrative event log page (EventLog.cshtml.cs) later deserializes this JSON and uses @Html.Raw to render the User-Agent value without proper HTML encoding. An unauthenticated attacker can trigger a loggable event (e.g., by requesting a non-existent attachment ID) with a malicious User-Agent header. When an administrator views the Event Log, the payload executes in their security context, leading to potential full site takeover. This issue is fixed in versions 4.0.5 and 3.2.12.
Affected products
- YAFNET YetAnotherForum.NET (YAF.NET) < 4.0.5, < 3.2.12
Timeline
- 2026-04-26: advisory: GitHub Security Advisory published
- 2026-05-12: disclosed: CVE published to NVD