CVE-2023-2850
25.07.2023, 12:15
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.Enginsight
Vendor | Product | Version |
---|---|---|
nodebb | nodebb | 𝑥 < 2.8.13 |
nodebb | nodebb | 3.0.0 ≤ 𝑥 < 3.1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References