CVE-2023-22468

Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed), are vulnerable to cross-site Scripting. A maliciously crafted URL can be included in a post to carry out cross-site  scripting attacks on sites with disabled or overly permissive CSP (Content Security Policy). Discourse's default CSP prevents this vulnerability. This vulnerability is patched in versions 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed). As a workaround, enable and/or restore your site's CSP to the default one provided with Discourse.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
GitHub_MCNA
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
discoursediscourse
𝑥
< 2.8.13
discoursediscourse
2.9.0:beta1
discoursediscourse
2.9.0:beta10
discoursediscourse
2.9.0:beta11
discoursediscourse
2.9.0:beta12
discoursediscourse
2.9.0:beta13
discoursediscourse
2.9.0:beta14
discoursediscourse
2.9.0:beta2
discoursediscourse
2.9.0:beta3
discoursediscourse
2.9.0:beta4
discoursediscourse
2.9.0:beta5
discoursediscourse
2.9.0:beta6
discoursediscourse
2.9.0:beta7
discoursediscourse
2.9.0:beta8
discoursediscourse
2.9.0:beta9
discoursediscourse
3.0.0:beta15
𝑥
= Vulnerable software versions