CVE-2021-21283: XSS in Flarum Sticky extension.

Published Jan 26, 2021
·
Updated

Flarum is an open source discussion platform for websites. The "Flarum Sticky" extension versions 0.1.0-beta.14 and 0.1.0-beta.15 has a cross-site scripting vulnerability. A change in release beta 14 of the Sticky extension caused the plain text content of the first post of a pinned discussion to be injected as HTML on the discussion list. The issue was discovered following an internal audit. Any HTML would be injected through the m.trust() helper. This resulted in an HTML injection where <script> tags would not be executed. However it was possible to run javascript from other HTML attributes, enabling a cross-site scripting (XSS) attack to be performed. Since the exploit only happens with the first post of a pinned discussion, an attacker would need the ability to pin their own discussion, or be able to edit a discussion that was previously pinned. On forums where all pinned posts are authored by your staff, you can be relatively certain the vulnerability has not been exploited. Forums where some user-created discussions were pinned can look at the first post edit date to find whether the vulnerability might have been exploited. Because Flarum doesn't store the post content history, you cannot be certain if a malicious edit was reverted. The fix will be available in version v0.1.0-beta.16 with Flarum beta 16. The fix has already been back-ported to Flarum beta 15 as version v0.1.0-beta.15.1 of the Sticky extension. Forum administrators can disable the Sticky extension until they are able to apply the update. The vulnerability cannot be exploited while the extension is disabled.

Affected Software

2 affected components
Flarum Sticky=0.1.0-beta14
Flarum Sticky=0.1.0-beta15

Event History

Jan 26, 2021
CVE Published
via MITRE·08:45 PM
Data Sourced
via MITRE·08:45 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2021-21283?

CVE-2021-21283 has a medium severity due to its cross-site scripting vulnerability in the Flarum Sticky extension.

2

How do I fix CVE-2021-21283?

To fix CVE-2021-21283, update the Flarum Sticky extension to version 0.1.0-beta.15 or later.

3

Which versions of Flarum Sticky are affected by CVE-2021-21283?

CVE-2021-21283 affects Flarum Sticky versions 0.1.0-beta.14 and 0.1.0-beta.15.

4

What type of vulnerability is CVE-2021-21283?

CVE-2021-21283 is a cross-site scripting vulnerability that affects the Flarum Sticky extension.

5

Is there a workaround for CVE-2021-21283?

There are no known workarounds for CVE-2021-21283; updating the extension is the recommended solution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203