PT-2022-24858 · Discotoc · Discotoc

Jomaxro

·

Published

2022-10-06

·

Updated

2022-11-10

·

CVE-2022-39270

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions DiscoTOC versions prior to the fixed version on the main branch
Description The issue allows users to inject arbitrary HTML on a topic's page if they can create topics in TOC-enabled categories and have a sufficient trust level. The estimated number of potentially affected devices is not provided. There is no information about real-world incidents where this issue was exploited.
Technical details about exploitation include the ability of users to inject arbitrary HTML, but specific API Endpoints, Vulnerable Parameters or Variables, and Function Names are not mentioned.
Recommendations For versions prior to the fixed version on the main branch, update the theme component through the admin UI (Customize -> Themes -> Components -> DiscoTOC -> Check for Updates). Alternatively, temporarily disable the DiscoTOC theme component as a quick mitigation measure.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-39270
GHSA-M44P-W923-W32H

Affected Products

Discotoc