Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, the lack of restrictions on the iFrame tag makes it easy for an attacker to exploit the vulnerability and hide subsequent comments from other users. This issue is patched in version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches. There are no known workarounds.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-06-13T21:16:09.257Z
Updated: 2024-08-02T15:03:28.699Z
Reserved: 2023-05-01T16:47:35.313Z
Link: CVE-2023-32061
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-06-13T22:15:09.477
Modified: 2024-11-21T08:02:38.113
Link: CVE-2023-32061
Redhat
No data.