#VU126534 Session Fixation in Flarum - CVE-2025-27794
Published: March 12, 2025 / Updated: April 20, 2026
Flarum
Flarum
Description
The vulnerability allows a remote attacker to hijack a user's session.
The vulnerability exists due to improper session management in session token handling when an attacker-controlled authoritative subdomain sets cookies scoped to the parent domain. A remote attacker can set a crafted cookie containing the attacker's session token to hijack a user's session.
User interaction is required, and exploitation is possible only when the parent domain is not on the Public Suffix List and the attacker controls a direct child subdomain.