Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the FriendsOfFlarum OAuth integration, specifically with the Discord provider, could allow an unauthenticated attacker to impersonate users, including administrators, by exploiting how email verification is handled during sign-in. This issue arises when the Discord OAuth provider incorrectly trusts unverified email addresses, enabling an attacker to link their Discord account to an existing Flarum user's identity. While other providers were not confirmed to be vulnerable, the potential impact on user accounts warrants attention.
- Attackers can impersonate users via Discord sign-in.
- Compromised accounts could include administrators.
- Confirm if Discord sign-in is enabled and assess exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker could exploit this vulnerability by tricking the Flarum forum into accepting a Discord account with an unverified email address as legitimate. If the Discord OAuth provider is enabled, the attacker can sign up for Discord using a known Flarum user's email address, even if that email isn't verified by Discord. By then logging into Flarum using this Discord account, the attacker can impersonate the legitimate Flarum user, potentially gaining administrative access.
- Attacker needs Discord account and victim's email.
- Triggered by Discord sign-in flow.
- Allows unauthorized account access.
Live Threat
Current exploitation, exposure, and threat context
The FriendsOfFlarum OAuth provider, when configured with Discord, could allow an unauthenticated attacker to impersonate existing users, including administrators. This occurs because the provider may not properly verify email addresses from Discord, enabling an attacker to link a Discord account with an unverified, but known, user email to that user's Flarum account. This could lead to unauthorized access and control over user accounts when Discord sign-in is enabled and the victim's email is not already linked to a Discord account.
- User accounts and administrator privileges.
- Linking attacker's Discord to victim's email.
- Unauthorized access and account compromise.
Operational Fix
Recommended remediation, mitigation, and detection steps
The FriendsOfFlarum OAuth provider, specifically its Discord integration, presents a critical risk for Flarum deployments. Given that OAuth services are typically internet-facing to enable external logins, application owners and platform teams should prioritize identifying all Flarum instances utilizing Discord OAuth. Confirming exposure and business criticality will inform the necessary triage and remediation planning.
- Identify Flarum instances using Discord OAuth.
- Verify Discord OAuth reachability and business impact.
- Plan remediation based on identified risk.