Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in the html of the post. The vulnerability is fixed in commit a62f711d5600e4e5d86f342d52932cb6221672e7.
History

Tue, 03 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Aug 2024 16:45:00 +0000

Type Values Removed Values Added
Description Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in the html of the post. The vulnerability is fixed in commit a62f711d5600e4e5d86f342d52932cb6221672e7.
Title Discourse Placeholder Forms has a XSS stopped by CSP
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-20T16:28:48.424Z

Updated: 2024-09-03T14:56:18.687Z

Reserved: 2024-08-12T18:02:04.966Z

Link: CVE-2024-43408

cve-icon Vulnrichment

Updated: 2024-09-03T14:56:12.707Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-20T17:15:19.550

Modified: 2024-08-21T12:30:33.697

Link: CVE-2024-43408

cve-icon Redhat

No data.