PT-2023-19077 · Discourse · Discourse
Pmusaraj
·
Published
2023-02-03
·
Updated
2024-03-06
·
CVE-2023-23615
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to the latest stable, beta and tests-passed versions
Description
The issue allows exploitation of embeddable comments to create new topics as any user without a clear title or content.
Recommendations
For versions prior to the latest stable, beta and tests-passed versions, update to the latest version to resolve the issue.
As a temporary workaround, consider disabling embeddable comments by deleting all embeddable hosts.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse