PT-2022-24994 · Nodebb · Nodebb

Julianlam

·

Published

2022-11-13

·

Updated

2022-11-18

·

CVE-2022-3978

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions NodeBB versions up to 2.5.7
Description A vulnerability was found in NodeBB, affecting an unknown part of the file /register/abort. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely.
Recommendations For NodeBB versions up to 2.5.7, upgrade to version 2.5.8 to address this issue. As a temporary workaround, consider restricting access to the /register/abort endpoint until the upgrade is applied.

Exploit

Fix

Incorrect Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-3978
GHSA-5GWX-WF9G-R5MX

Affected Products

Nodebb