PT-2023-18511 · Discourse · Discourse

Jomaxro

·

Published

2023-01-05

·

Updated

2024-03-06

·

CVE-2023-22455

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2.8.14 Discourse versions prior to 3.0.0.beta16
Description The issue affects Discourse, an open-source discussion platform, where tag descriptions can be used for cross-site scripting attacks. This can lead to a full XSS on sites with modified or disabled Content Security Policy.
Recommendations For versions prior to 2.8.14, update to version 2.8.14 or later. For versions prior to 3.0.0.beta16, update to version 3.0.0.beta16 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2023-22455
CVE-2023-22455
GHSA-5RQ6-466R-6MR9

Affected Products

Discourse