← volver
CVE-2024-52794

Magnific lightbox susceptible to Cross-site Scripting in Discourse

CVSS 6.8 MEDIUMEPSS 0.3%CWE-79
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.8EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
19 dic 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L
Productos afectados
discourse · discourse

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →