PT-2021-22418 · Discourse · Discourse

Oblakeerickson

·

Published

2021-08-26

·

Updated

2024-03-06

·

CVE-2021-39161

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest stable, beta and tests-passed versions
Description The issue allows category names to be used for Cross-site scripting (XSS) attacks. This is mitigated by Discourse's default Content Security Policy, and the vulnerability only affects sites that have modified, disabled, or changed this policy and have allowed moderators to modify categories.
Recommendations For all affected versions, ensure that the Content Security Policy is enabled and has not been modified in a way that would make it more vulnerable to XSS attacks. Update to the latest stable, beta, or tests-passed version of Discourse to patch the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2021-39161
CVE-2021-39161
GHSA-XHMC-9JWM-WQPH

Affected Products

Discourse