Sploitus

CVE-2023-22468

No indexed exploits for CVE-2023-22468 yet

Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed), are vulnerable to cross-site Scripting. A maliciously crafted URL can be included in a post to carry out cross-site scripting attacks on sites with disabled or overly permissive CSP (Content Security Policy). Discourse's default CSP prevents this vulnerability. This vulnerability is patched in versions 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed). As a workaround, enable and/or restore your site's CSP to the default one provided with Discourse.

Affected products
Discourse
Discourse
< 2.8.13, 2.9.0, 3.0.0
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
0.5% (40th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2023-01-26
CVE-2023-22468 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-22468 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-22468 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.