PT-2024-28445 · Discourse · Discourse

0Xmokusou

·

Published

2024-07-30

·

Updated

2024-09-11

·

CVE-2024-39320

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.2.5 Discourse versions prior to 3.3.0.beta5
Description The issue allows an attacker to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed iframes setting.
Recommendations For versions prior to 3.2.5, update to version 3.2.5 or later. For versions prior to 3.3.0.beta5, update to version 3.3.0.beta5 or later.

Exploit

Fix

Clickjacking

Special Elements Injection

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2024-39320
CVE-2024-39320
GHSA-4P82-XH38-GQ4P

Affected Products

Discourse