
Cloud Vulnerability DB
A community-led vulnerabilities database
The Flarum Sticky extension versions 0.1.0-beta.14 and 0.1.0-beta.15 contained a cross-site scripting (XSS) vulnerability identified as CVE-2021-21283. The vulnerability was discovered through an internal audit and was introduced by a change in beta 14 that caused plain text content of pinned discussions' first posts to be incorrectly rendered as HTML on the discussion list (Flarum Advisory).
The vulnerability stemmed from the improper use of Mithril's m.trust() helper function, which caused HTML injection in the discussion list. While <script> tags would not be executed directly, attackers could still execute JavaScript through other HTML attributes. The issue was fixed by modifying how the content was wrapped in the ItemList entries, changing from direct m.trust() evaluation to proper vnode handling (GitHub PR).
The vulnerability allowed for cross-site scripting attacks through pinned discussions. The attack required either the ability to pin discussions or edit previously pinned discussions. Forums where pinned posts were exclusively authored by staff members were at lower risk, while those allowing user-created pinned discussions were more vulnerable. Due to Flarum's lack of post content history, it was difficult to determine if malicious edits had been made and reverted (Flarum Advisory).
The vulnerability could be exploited by users with permissions to pin discussions or edit pinned discussions. The exploit involved injecting malicious HTML content into the first post of a pinned discussion, which would then be rendered unsafely on the discussion list (GitHub Advisory).
The vulnerability was patched in version v0.1.0-beta.15.1 for Flarum beta 15 users. For beta 14 users, the recommended action was to disable the Sticky extension until upgrading to beta 15. Users on beta 13 were not affected but were advised to upgrade to beta 15 for continued security support. As a temporary workaround, administrators could disable the Sticky extension entirely to prevent exploitation (Flarum Advisory).
The Flarum community responded positively to the security update, with users successfully implementing the patch. There were discussions about improving the security update notification system, with suggestions for implementing direct admin panel alerts and various notification channels including blog subscriptions, Discord announcements, and GitHub release notifications (Flarum Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."