Path traversal in Flarum - CVE-2023-27577
Published: March 10, 2023 / Updated: April 20, 2026
Flarum
Flarum
Description
The vulnerability allows a remote user to read sensitive server files.
The vulnerability exists due to path traversal in the LESS parser when processing custom LESS settings. A remote privileged user can provide an absolute path to a sensitive file to read sensitive server files.
Exploitation requires control of an admin account.