PT-2023-18511 · Discourse · Discourse

Jomaxro

·

Publicado

2023-01-05

·

Atualizado

2024-03-06

·

CVE-2023-22455

CVSS v3.1

6.8

Média

VetorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2.8.14 Discourse versions prior to 3.0.0.beta16
Description The issue affects Discourse, an open-source discussion platform, where tag descriptions can be used for cross-site scripting attacks. This can lead to a full XSS on sites with modified or disabled Content Security Policy.
Recommendations For versions prior to 2.8.14, update to version 2.8.14 or later. For versions prior to 3.0.0.beta16, update to version 3.0.0.beta16 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-DISCOURSE-2023-22455
CVE-2023-22455
GHSA-5RQ6-466R-6MR9

Produtos afetados

Discourse