Vulnerabilities
Vulnerable Software
Discourse:  >> Discourse  >> 2.7.7  Security Vulnerabilities
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta5, a user's read state for a topic such as the last read post number and the notification level is exposed.
CVSS Score
4.3
EPSS Score
0.008
Published
2021-08-13
Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy. This issue is patched in the latest `stable` 2.7.8 version of Discourse. As a workaround users may ensure that the Content Security Policy is enabled, and has not been modified in a way which would make it more vulnerable to XSS attacks.
CVSS Score
7.4
EPSS Score
0.008
Published
2021-08-09


Contact Us

Shodan ® - All rights reserved