Description
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.
Problem types
Product status
Credits
Jai Niresh J
Hypixel Inc.
References
xenforo.com/...-3-7-released-includes-security-fixes.232121/ (XenForo 2.3.7 Released (Includes Security Fixes))
www.vulncheck.com/advisories/xenforo-passkey-security-bypass (VulnCheck Advisory: XenForo Passkey Security Bypass)