Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-46180

Опубликовано: 04 янв. 2023
Источник: nvd
CVSS3: 5
CVSS3: 5.4
EPSS Низкий

Описание

Discourse Mermaid (discourse-mermaid-theme-component) allows users of Discourse, open-source forum software, to create graphs using the Mermaid syntax. Users of discourse-mermaid-theme-component version 1.0.0 who can create posts are able to inject arbitrary HTML on that post. The issue has been fixed on the main branch of the GitHub repository, with 1.1.0 named as a patched version. Admins can update the theme component through the admin UI. As a workaround, admins can temporarily disable discourse-mermaid-theme-component.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:discourse:mermaid:*:*:*:*:*:*:*:*
Версия от 1.0.0 (включая) до 1.1.0 (исключая)

EPSS

Процентиль: 60%
0.00406
Низкий

5 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-74
CWE-79

EPSS

Процентиль: 60%
0.00406
Низкий

5 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-74
CWE-79