Описание
discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with the discourse-bccode plugin. This vulnerability only affects sites which have the discourse-bbcode plugin installed and enabled. This issue is patched in commit 91478f5. As a workaround, ensure that the Content Security Policy is enabled and monitor any posts that contain bbcode.
Ссылки
- PatchThird Party Advisory
- ExploitVendor Advisory
- PatchThird Party Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2022-11-30 (исключая)
cpe:2.3:a:discourse:discourse_bbcode:*:*:*:*:*:discourse:*:*
EPSS
Процентиль: 78%
0.01151
Низкий
8.8 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-74
CWE-79
EPSS
Процентиль: 78%
0.01151
Низкий
8.8 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-74
CWE-79