PT-2019-14237 · Discourse · Discourse

Published

2019-08-26

·

Updated

2019-08-29

·

CVE-2019-15515

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse version 2.3.2
Description The issue involves Discourse sending the CSRF token in the query string, which could potentially be exploited.
Recommendations For Discourse version 2.3.2, consider updating to a newer version that does not send the CSRF token in the query string, or as a temporary workaround, restrict access to sensitive operations that rely on the CSRF token.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15515

Affected Products

Discourse