icon

We found results for “

CVE-2023-32061

Date: June 13, 2023

Discourse is an open source discussion platform. Prior to version 3.0.4 of the "stable" branch and version 3.1.0.beta5 of the "beta" and "tests-passed" branches, the lack of restrictions on the iFrame tag makes it easy for an attacker to exploit the vulnerability and hide subsequent comments from other users. This issue is patched in version 3.0.4 of the "stable" branch and version 3.1.0.beta5 of the "beta" and "tests-passed" branches. There are no known workarounds.

Language: Ruby

Severity Score

Severity Score

Weakness Type (CWE)

Incorrect Authorization

CWE-863

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): LOW
Availability (A): LOW

Do you need more information?

Contact Us