PT-2023-19077 · Discourse · Discourse

Pmusaraj

·

Published

2023-02-03

·

Updated

2024-03-06

·

CVE-2023-23615

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest stable, beta and tests-passed versions
Description The issue allows exploitation of embeddable comments to create new topics as any user without a clear title or content.
Recommendations For versions prior to the latest stable, beta and tests-passed versions, update to the latest version to resolve the issue. As a temporary workaround, consider disabling embeddable comments by deleting all embeddable hosts.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2023-23615
CVE-2023-23615
GHSA-7MF3-5V84-WXQ8

Affected Products

Discourse