PT-2023-3566 · Discourse · Discourse
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to the latest stable, beta and tests-passed version
Description
The issue is related to insufficient input validation when processing topic titles, allowing a remote attacker to impact the integrity and availability of protected information. The vulnerability enables a user to bypass topic title validations, such as title length, number of emojis in the title, and blank topic titles, when editing a topic.
Recommendations
For versions prior to the latest stable, beta and tests-passed version, update to the latest stable, beta or tests-passed version to resolve the issue. As a temporary workaround, consider restricting the ability to edit topic titles until the update is applied.
Exploit
Fix
DoS
Improper Authentication
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Discourse