Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39270

Опубликовано: 06 окт. 2022
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component's settings) are able to inject arbitrary HTML on that topic's page. The issue has been fixed on the main branch. Admins can update the theme component through the admin UI (Customize -> Themes -> Components -> DiscoTOC -> Check for Updates). Alternatively, admins can temporarily disable the DiscoTOC theme component.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:discourse:discotoc:*:*:*:*:*:*:*:*
Версия до 2.1.0 (исключая)

EPSS

Процентиль: 44%
0.00213
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

EPSS

Процентиль: 44%
0.00213
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79