Back to Research blog

Advisory: Flarum LFI - CVE-2023-40033

Share on social

August 28, 2023

Lorem ipsum

Table of Contents

Summary

An attacker with a basic user forum account can specify a malicious avatar URL that discloses the contents of arbitrary local files on the file system.

Impact

An attacker can read the contents of any local file. An attacker can also conduct blind SSRF attacks.

Affected Software

The following versions are affected by this vulnerability:

  • flarum/framework < 1.8.0

Product Description

Flarum is a delightfully simple discussion platform for your website. It’s fast, free, and easy to use, with all the features you need to run a successful community. It’s also extremely extensible, allowing for ultimate customizability.

Solution

Upgrade to the latest version of flarum/framework, >= 1.8.0.

Flarum has released an advisory here. The vulnerability was assigned CVE-2023-40033.

Blog Post

The blog post detailing the steps taken for the discovery of this vulnerability can be found here.

Credits

Adam Kues - Assetnote Security Research Team

Adam Kues

Author

Adam Kues

Security Researcher at Searchlight Cyber

Explore related Content

Research

Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25

July 20, 2026

Research

wp2shell: Pre Authentication RCE in WordPress Core

July 17, 2026

Research

Smashing the ServiceNow Sandbox – Pre Authentication RCE

July 14, 2026

Research

CargoWise WebTracker – The Keys Were in the Cargo

June 25, 2026

Research

Two Bypasses for Chrome's Sanitizer API

May 22, 2026

Research

Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)

May 21, 2026