S4E just found a medium-severity finding from self signed ssl certificate detection
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Apr 28, 2025

CVE-2024-21641 Scanner

CVE-2024-21641 Scanner - Open Redirect vulnerability in Flarum

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-21641
4.7
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Flarum is open source discussion platform software. Prior to version 1.8.5, the Flarum `/logout` route includes a redirect parameter that allows any third party to redirect users from a (trusted) domain of the Flarum installation to redirect to any link. For logged-in users, the logout must be confirmed. Guests are immediately redirected. This could be used by spammers to redirect to a web address using a trusted domain of a running Flarum installation. The vulnerability has been fixed and published as flarum/core v1.8.5. As a workaround, some extensions modifying the logout route can remedy this issue if their implementation is safe.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
frameworkby flarum
< 1.8.5
Updated Aug 22, 2026View on NVD →
Detail

Flarum is an open-source forum software widely used to create online discussion platforms. It is favored for its lightweight design and flexibility, enabling community building and interaction. Developers and community managers use it to host forums where users can discuss various topics, share information, and collaborate. The software supports multiple extensions, allowing customization to meet diverse user needs. With a focus on simplicity and efficiency, Flarum is utilized by web developers and administrators of all experience levels. The product is continually updated to enhance user experience and security.

The Open Redirect vulnerability in Flarum exists in its `/logout` route, affecting versions prior to 1.8.5. This vulnerability allows third parties to misuse redirect parameters, taking users to unexpected destinations. For authenticated users, confirmation is required for redirection, while unauthenticated users are redirected immediately. Such vulnerabilities can be exploited by attackers to perform phishing attacks by redirecting users to malicious domains. Ensuring safe web navigation and preventing untrusted redirects is crucial to maintaining user trust in web applications.

Technically, the vulnerability is present in the `/logout` endpoint, where the redirect parameter can be manipulated. A malicious actor can insert an arbitrary external link, causing users to be redirected to potentially harmful websites. The issue arises due to the lack of stringent parameter validation, allowing any inserted URL to be utilized. This technical flaw can be leveraged by attackers during phishing campaigns, leveraging the trusted domain to lure users into revealing sensitive information unknowingly. Proper handling and validation of redirect parameters are essential to mitigating this risk.

If exploited, the open redirect vulnerability can lead to serious security concerns, including user data theft and unauthorized access. Threat actors may exploit the vulnerability to execute phishing attacks, tricking users into entering sensitive information on malicious websites. Redirecting to compromised sites can expose users to malware, adware, or other harmful software. Moreover, user trust in the platform may be undermined, causing reputational damage. Addressing this vulnerability is crucial to maintaining security and protecting users from potential exploitation.

REFERENCES

Solution Advice
  • Update Flarum to version 1.8.5 or later to resolve the open redirect vulnerability.
  • Ensure any third-party extensions modifying the logout route are securely implemented.
  • Implement robust parameter validation for redirects to prevent unauthorized URL usage.
  • Conduct regular security audits on web applications to identify and mitigate vulnerabilities.
  • Inform users about potential phishing risks and provide guidance on avoiding malicious redirects.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.