Discourse is an open source platform for community discussion. In affected versions with some combinations of plugins, and with CSP disabled, activity streams in the user's profile page may be vulnerable to XSS. This has been patched in the latest version of Discourse core. Users are advised to upgrade. Users unable to upgrade should ensure CSP is enabled.
History

Tue, 04 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Feb 2025 21:30:00 +0000

Type Values Removed Values Added
Description Discourse is an open source platform for community discussion. In affected versions with some combinations of plugins, and with CSP disabled, activity streams in the user's profile page may be vulnerable to XSS. This has been patched in the latest version of Discourse core. Users are advised to upgrade. Users unable to upgrade should ensure CSP is enabled.
Title Cross-site Scripting (XSS) via topic titles when CSP disabled in Discourse
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-04T21:40:25.211Z

Reserved: 2024-11-19T20:08:14.481Z

Link: CVE-2024-53266

cve-icon Vulnrichment

Updated: 2025-02-04T21:40:20.746Z

cve-icon NVD

Status : Received

Published: 2025-02-04T22:15:40.347

Modified: 2025-02-04T22:15:40.347

Link: CVE-2024-53266

cve-icon Redhat

No data.