SB2019070512 - Cross-site request forgery in Flarum
Published: July 5, 2019 Updated: April 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site request forgery (CVE-ID: CVE-2019-13183)
The vulnerability allows a remote attacker to perform actions on behalf of a victim user.
The vulnerability exists due to improper request verification in CSRF protection in flarum/core when handling crafted cross-site requests from a victim's browser. A remote attacker can trick a logged-in user into visiting a malicious site to perform actions on behalf of a victim user.
An attacker who targets a user with admin privileges may manipulate administrative settings.
Remediation
Install update from vendor's website.