Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-26145

Опубликовано: 21 фев. 2024
Источник: nvd
CVSS3: 6.5
CVSS3: 4.3
EPSS Низкий

Описание

Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited users are able to gain access to private events by crafting a request to update their attendance. This problem is resolved in commit dfc4fa15f340189f177a1d1ab2cc94ffed3c1190. As a workaround, one may use post visibility to limit access.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:discourse:calendar:*:*:*:*:*:*:*:*
Версия до 2024-02-21 (исключая)

EPSS

Процентиль: 37%
0.00158
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-863
NVD-CWE-noinfo

EPSS

Процентиль: 37%
0.00158
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-863
NVD-CWE-noinfo