CVE-2024-58342: XenForo Open Redirect via getDynamicRedirect
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs containing newlines, user credentials, or host mismatches.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58342?
CVE-2024-58342 is classified as a high severity vulnerability due to its potential for open redirects.
How do I fix CVE-2024-58342?
To fix CVE-2024-58342, update XenForo to version 2.2.17 or later, or 2.3.1 or later.
What versions of XenForo are affected by CVE-2024-58342?
CVE-2024-58342 affects XenForo versions prior to 2.2.17 and 2.3.1.
What type of vulnerability is CVE-2024-58342?
CVE-2024-58342 is an open redirect vulnerability that can lead to redirecting users to malicious external sites.
Can attackers exploit CVE-2024-58342?
Yes, attackers can exploit CVE-2024-58342 by crafting specially designed URLs to redirect users.