NA

CVE-2023-22454

Published: 05/01/2023 Updated: 13/01/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, pending post titles can be used for cross-site scripting attacks. Pending posts can be created by unprivileged users when a category has the "require moderator approval of all new topics" setting set. This vulnerability can lead to a full XSS on sites which have modified or disabled Discourse’s default Content Security Policy. A patch is available in versions 2.8.14 and 3.0.0.beta16.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

discourse discourse

discourse discourse 1.1.0

discourse discourse 1.2.0

discourse discourse 1.3.0

discourse discourse 1.4.0

discourse discourse 1.5.0

discourse discourse 1.6.0

discourse discourse 1.7.0

discourse discourse 1.8.0

discourse discourse 1.9.0

discourse discourse 2.0.0

discourse discourse 2.1.0

discourse discourse 2.2.0

discourse discourse 2.3.0

discourse discourse 2.4.0

discourse discourse 2.5.0

discourse discourse 2.6.0

discourse discourse 2.7.0

discourse discourse 2.8.0

discourse discourse 2.9.0

discourse discourse 3.0.0