CVE-2023-22455

MEDIUM6.1EPSS 0.46%

Discourse vulnerable to Cross-site Scripting through tag descriptions

發布日:2024/3/6修改日:2025/10/15
也稱為:GHSA-5rq6-466r-6mr9BIT-discourse-2023-22455

描述

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, tag descriptions, which can be updated by moderators, can be used for cross-site scripting attacks. This vulnerability can lead to a full XSS on sites which have modified or disabled Discourse’s default Content Security Policy. Versions 2.8.14 and 3.0.0.beta16 contain a patch.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

參考連結(3)