VWE-2021-6259 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2021-6259
This page is a chapter in Info Known Vulnerabilities

This page has been seen 111,190 times.

    • Created by on
Common NameNone
VWE-IDVWE-2021-6259
Related ReportNone
SeverityExtreme
Exploit DifficultyNORMAL
PlatformXenForo 2.x
DescriptionDenial of Service amplification. A distributed attack by malicious editors can consume all memory allocated to PHP by leveraging massive numbers of template inclusions within complex template fields and saving the affected pages simultaneously. Does not affect Lite versions.
DiscoveredOctober 19, 2021
ResolvedOctober 25, 2021
Patches Available4.1.2 Patch Level 3
4.1.1 Patch Level 8
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.