Executive brief
XenForo is a popular web forum platform. The platform's OAuth2 authentication system fails to verify that an authorization code is redeemed with the same redirect URI where it was originally issued, allowing an attacker with control of an alternative registered callback to steal OAuth2 tokens from legitimate user authorization flows.
Technical details
XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint where the authorization code is not bound to the redirect URI used during the authorization request. The server stores the redirect URI on the OAuthRequest object but only validates that the submitted redirect_uri parameter appears in the client's allowlist during token redemption, without comparing it to the URI that originally issued the code. An attacker controlling a second allowlisted redirect URI can intercept or obtain a valid authorization code issued for a different callback and redeem it using their controlled callback URI. The attack requires a valid authorization code and control of another registered callback (e.g., an abandoned endpoint or custom URI scheme), but does not require code interception or credential compromise. XenForo 2.3.13 fixes this by binding the submitted redirect URI to the authorization request that produced the code.
Affected products
- XenForo XenForo before 2.3.13
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Fixed in XenForo 2.3.13