Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after v1.5 and was not noticed. This allowed an attacker to inject malicious HTML markup using a discussion title input, either by creating a new discussion or renaming one. The XSS attack occurs after a visitor opens the relevant discussion page. All communities running Flarum from v1.5.0 to v1.6.1 are impacted. The vulnerability has been fixed and published as flarum/core v1.6.2. All communities running Flarum from v1.5.0 to v1.6.1 have to upgrade as soon as possible to v1.6.2. There are no known workarounds for this issue.
CVE-2022-41938
This critical-severity CVE scores 9.0 under NVD CVSS v3. EPSS exploit probability: 0.7%, top 51% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.0
- EG Score
- 9.0(medium)
- EG Risk
- 41(Track)EG Risk 41/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation1% × 40%Automatability0% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 1%
- EPSS %ILE
- 53%
- KEV
- Not listed
Published
November 19, 2022
Last Modified
November 21, 2024
References (6)
- security-advisories@githubhttps://discuss.flarum.org/d/27558
- security-advisories@githubhttps://github.com/flarum/framework/commit/690de9ce0ffe7ac4d45b73e303f44340c3433138
- security-advisories@githubhttps://github.com/flarum/framework/security/advisories/GHSA-7x4w-j98p-854x
- af854a3a-2127-422b-91ae-364da2661108https://discuss.flarum.org/d/27558
- af854a3a-2127-422b-91ae-364da2661108https://github.com/flarum/framework/commit/690de9ce0ffe7ac4d45b73e303f44340c3433138
- af854a3a-2127-422b-91ae-364da2661108https://github.com/flarum/framework/security/advisories/GHSA-7x4w-j98p-854x
Related CVEs
Related CVEs are temporarily unavailable — the same-product, same-vendor and same-CWE lists could not be loaded just now. That is not a sign that none exist; please retry shortly.
Frequently asked(5)
What is CVE-2022-41938?
When was CVE-2022-41938 disclosed?
Is CVE-2022-41938 actively exploited?
What is the CVSS score of CVE-2022-41938?
How do I remediate CVE-2022-41938?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2022-41938
Is Your Infrastructure Affected by CVE-2022-41938?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.