CVE-2025-71280: XenForo Local Account Page Caching Information Disclosure
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71280?
CVE-2025-71280 is considered a medium severity vulnerability due to the potential unauthorized access to sensitive user information.
How do I fix CVE-2025-71280?
To fix CVE-2025-71280, upgrade your XenForo installation to version 2.3.7 or later, which includes a security patch.
What are the potential impacts of CVE-2025-71280?
The potential impacts of CVE-2025-71280 include unauthorized access to cached sensitive user information by other local users.
Who is affected by CVE-2025-71280?
CVE-2025-71280 affects users of XenForo versions prior to 2.3.7 installed on shared systems.
What is the nature of the vulnerability in CVE-2025-71280?
CVE-2025-71280 is an information disclosure vulnerability related to local account page caching on shared systems.