CVE-2020-24327
23.09.2021, 18:15
Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.
| Vendor | Product | Version |
|---|---|---|
| discourse | discourse | 2.3.2 |
| discourse | discourse | 2.6.0 |
𝑥
= Vulnerable software versions
References