PT-2025-3268 · Discourse · Discourse
Jomaxro
·
Published
2025-02-04
·
Updated
2025-09-26
·
CVE-2024-56328
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Discourse (affected versions not specified)
Description
The issue allows an attacker to execute arbitrary JavaScript code in users' browsers by posting a maliciously crafted Onebox URL. This problem only affects sites with Content Security Policy (CSP) disabled. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
The technical details about exploitation include the use of a malicious Onebox URL to execute arbitrary JavaScript code.
Recommendations
For all affected versions, update to the latest version of Discourse to resolve the issue.
As a temporary workaround, consider enabling CSP, disabling inline Oneboxes globally, or allowing specific domains for Oneboxing until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse