Cross-site request forgery in Flarum - CVE-2019-13183
Published: July 5, 2019 / Updated: April 20, 2026
Flarum
Detailed vulnerability description
The vulnerability allows a remote attacker to perform actions on behalf of a victim user.
The vulnerability exists due to improper request verification in CSRF protection in flarum/core when handling crafted cross-site requests from a victim's browser. A remote attacker can trick a logged-in user into visiting a malicious site to perform actions on behalf of a victim user.
An attacker who targets a user with admin privileges may manipulate administrative settings.