NA

CVE-2022-31184

Published: 01/08/2022 Updated: 09/08/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to send mass spam emails. A fix has been included in the latest stable, beta and tests-passed versions of Discourse which rate limits emails. Users are advised to upgrade. Users unable to upgrade should manually rate limit email.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

discourse discourse 2.9.0

discourse discourse