SCA: security update for flarum/core (GHSA-7x4w-j98p-854x)

medium Tenable Cloud Security Plugin ID 412328

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be
converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not
noticed. This allowed an attacker to inject malicious HTML markup using a discussion title input, either
by creating a new discussion or renaming one. The XSS attack occurs after a visitor opens the relevant
discussion page. All communities running Flarum from `v1.5.0` to `v1.6.1` are impacted. The vulnerability
has been fixed and published as flarum/core `v1.6.2`. All communities running Flarum from `v1.5.0` to
`v1.6.1` have to upgrade as soon as possible to v1.6.2. There are no known workarounds for this issue.
(CVE-2022-41938)

See Also

https://github.com/advisories/GHSA-7x4w-j98p-854x

Plugin Details

Severity: Medium

ID: 412328

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 8.67

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2022-41938

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 11/21/2022

Vulnerability Publication Date: 11/19/2022

Reference Information

CVE: CVE-2022-41938

cwe: CWE-79