Discourse是一套开源的社区讨论平台。该平台包括社区、电子邮件和聊天室等功能。 Discourse 2.8.9之前版本、2.9.0.beta9之前版本存在安全漏洞,攻击者利用该漏洞可以将大量文本负载添加到用户配置文件的位置和网站字段中,这会在加载该配置文件时给其他用户带来问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-36066 | 9.1 CRITICAL | Discourse vulnerable to RCE via admins uploading maliciously zipped file |
| CVE-2022-36068 | 7.2 HIGH | Discourse moderators can edit themes via the API |
| CVE-2022-39232 | 6.5 MEDIUM | Discourse vulnerable to incomplete quote causing a topic to crash in the browser |
No comments yet