Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-48048 | Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Scripting attacks via the digest email preview UI. This issue only affects sites with CSP disabled. This issue has been patched in the 3.1.1 stable release as well as the 3.2.0.beta1 release. Users are advised to upgrade. Users unable to upgrade should ensure CSP is enabled on the forum. |
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-16T15:51:43.554Z
Reserved: 2023-09-20T15:35:38.148Z
Link: CVE-2023-43659
Updated: 2024-08-02T19:44:43.790Z
Status : Modified
Published: 2023-10-16T22:15:12.237
Modified: 2026-06-17T06:26:10.490
Link: CVE-2023-43659
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD