CVE-2023-32061: Discourse Topic Creation Page Allows iFrame Tag without Restrictions
Discourse is an open source discussion platform. Prior to version 3.0.4 of the stable branch and version 3.1.0.beta5 of the beta and tests-passed branches, the lack of restrictions on the iFrame tag makes it easy for an attacker to exploit the vulnerability and hide subsequent comments from other users. This issue is patched in version 3.0.4 of the stable branch and version 3.1.0.beta5 of the beta and tests-passed branches. There are no known workarounds.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-32061?
CVE-2023-32061 is a vulnerability in the Discourse open source discussion platform that allows an attacker to hide subsequent comments from other users.
What is the severity of CVE-2023-32061?
The severity of CVE-2023-32061 is medium with a CVSS score of 5.3.
Which versions of Discourse are affected by CVE-2023-32061?
Versions up to and including Discourse 3.0.4 of the stable branch and Discourse 3.1.0.beta5 of the beta and tests-passed branches are affected by CVE-2023-32061.
How can an attacker exploit CVE-2023-32061?
An attacker can exploit CVE-2023-32061 by taking advantage of the lack of restrictions on the iFrame tag in Discourse, allowing them to hide subsequent comments from other users.
Is there a fix for CVE-2023-32061?
Yes, upgrading to Discourse version 3.0.4 of the stable branch or version 3.1.0.beta5 of the beta and tests-passed branches will fix CVE-2023-32061.