Discourse是一套开源的社区讨论平台。该平台包括社区、电子邮件和聊天室等功能。 Discourse 2.8.14之前版本存在代码问题漏洞,该漏洞源于当用户请求密码重置链接邮件,然后改变他们的主邮件,旧的重置邮件仍然有效,当旧的重置邮件被用来重置密码时,Discourse账户的主邮件将被重新链接到旧邮件,如果旧的电子邮件地址被泄露或所有权被转移,这将导致账户接管。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-22454 | 8.0 HIGH | Discourse vulnerable to Cross-site Scripting through pending post titles descriptions |
| CVE-2023-22455 | 6.8 MEDIUM | Discourse vulnerable to Cross-site Scripting through tag descriptions |
| CVE-2022-23548 | 6.5 MEDIUM | Discourse 跨站脚本漏洞 |
| CVE-2022-23549 | 5.7 MEDIUM | Discourse vulnerable to bypass of post max_length using HTML comments |
| CVE-2022-23546 | 5.5 MEDIUM | Discourse vulnerable to private topic leak via email#send_digest |
| CVE-2023-22453 | 5.3 MEDIUM | Discourse vulnerable to exposure of user post counts per topic to unauthorized users |
| CVE-2022-46168 | 3.5 LOW | Group SMTP user emails are exposed in CC email header |
No comments yet