CVE-2019-11514: High severity flarum sticky vulnerability
User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens.
Other sources
User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11514?
CVE-2019-11514 is categorized as a high-severity vulnerability due to improper handling of user email tokens in Flarum.
How do I fix CVE-2019-11514?
To fix CVE-2019-11514, upgrade to Flarum version 0.1.0-beta.8 or later.
What versions of Flarum are affected by CVE-2019-11514?
CVE-2019-11514 affects Flarum versions prior to 0.1.0-beta.8, including various beta versions from 0.1.0-beta to 0.1.0-beta7.2.
What is the impact of CVE-2019-11514 on users?
The impact of CVE-2019-11514 involves potential security risks regarding unauthorized access through invalidated email tokens.
Is there a workaround for CVE-2019-11514 if I cannot upgrade?
There are no officially recommended workarounds for CVE-2019-11514 other than upgrading to a patched version.