SB2025031285 - Session Fixation in Flarum
Published: March 12, 2025 Updated: April 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Session Fixation (CVE-ID: CVE-2025-27794)
The vulnerability allows a remote attacker to hijack a user's session.
The vulnerability exists due to improper session management in session token handling when an attacker-controlled authoritative subdomain sets cookies scoped to the parent domain. A remote attacker can set a crafted cookie containing the attacker's session token to hijack a user's session.
User interaction is required, and exploitation is possible only when the parent domain is not on the Public Suffix List and the attacker controls a direct child subdomain.
Remediation
Install update from vendor's website.