PT-2023-3566 · Discourse · Discourse
Jomaxro
·
Published
2023-06-21
·
Updated
2024-03-06
·
CVE-2023-36466
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to the latest stable, beta and tests-passed version
Description
The issue is related to insufficient input validation when processing topic titles, allowing a remote attacker to impact the integrity and availability of protected information. The vulnerability enables a user to bypass topic title validations, such as title length, number of emojis in the title, and blank topic titles, when editing a topic.
Recommendations
For versions prior to the latest stable, beta and tests-passed version, update to the latest stable, beta or tests-passed version to resolve the issue. As a temporary workaround, consider restricting the ability to edit topic titles until the update is applied.
Exploit
Fix
RCE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Discourse