Discourse是一套开源的社区讨论平台。该平台包括社区、电子邮件和聊天室等功能。 Discourse 2.8.14之前版本(stable)、2.9.0.beta16之前版本(beta和tests-passed)存在安全漏洞。攻击者利用该漏洞可以通过包含不计入字符限制的html注释来创建原始正文长于“max_length”站点设置的帖子。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-22454 | 8.0 HIGH | Discourse vulnerable to Cross-site Scripting through pending post titles descriptions |
| CVE-2023-22455 | 6.8 MEDIUM | Discourse vulnerable to Cross-site Scripting through tag descriptions |
| CVE-2022-23548 | 6.5 MEDIUM | Discourse 跨站脚本漏洞 |
| CVE-2022-46177 | 5.7 MEDIUM | Discourse password reset link can lead to in account takeover if user changes to a new ema |
| CVE-2022-23546 | 5.5 MEDIUM | Discourse vulnerable to private topic leak via email#send_digest |
| CVE-2023-22453 | 5.3 MEDIUM | Discourse vulnerable to exposure of user post counts per topic to unauthorized users |
| CVE-2022-46168 | 3.5 LOW | Group SMTP user emails are exposed in CC email header |
No comments yet