Cross-site Scripting via email preview when CSP disabled in Discourse
CVE-2023-43659
What is CVE-2023-43659?
An improper escaping of user input within the digest email preview UI of the Discourse community platform poses a vulnerability that can be exploited for Cross-site Scripting (XSS) attacks. This issue specifically impacts installations where Content Security Policy (CSP) is disabled. To mitigate the risk, users are encouraged to upgrade to the patched versions, namely Discourse 3.1.1 or Discourse 3.2.0.beta1. For users unable to perform an upgrade, enabling CSP on forums is essential for enhancing security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
discourse stable <= 3.1.1 <= stable 3.1.1
discourse beta <= 3.2.0.beta1 <= beta 3.2.0.beta1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved