Description
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.
Problem types
Exposure of Sensitive Information to an Unauthorized Actor
Product status
Credits
Jai Niresh J
Hypixel Inc.
References
xenforo.com/...-3-7-released-includes-security-fixes.232121/ (XenForo 2.3.7 Released (Includes Security Fixes))
www.vulncheck.com/...unt-page-caching-information-disclosure (VulnCheck Advisory: XenForo Local Account Page Caching Information Disclosure)