PT-2023-3566 · Discourse · Discourse
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to the latest stable, beta and tests-passed version
Description
The issue is related to insufficient input validation when processing topic titles, allowing a remote attacker to impact the integrity and availability of protected information. The vulnerability enables a user to bypass topic title validations, such as title length, number of emojis in the title, and blank topic titles, when editing a topic.
Recommendations
For versions prior to the latest stable, beta and tests-passed version, update to the latest stable, beta or tests-passed version to resolve the issue. As a temporary workaround, consider restricting the ability to edit topic titles until the update is applied.
Exploit
Correção
DoS
Improper Authentication
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Discourse