CVE-2024-43408: Discourse Placeholder Forms has a XSS stopped by CSP
Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in the html of the post. The vulnerability is fixed in commit a62f711d5600e4e5d86f342d52932cb6221672e7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43408?
CVE-2024-43408 is classified as a medium severity vulnerability due to unsanitized user input being injected into HTML.
How do I fix CVE-2024-43408?
To fix CVE-2024-43408, upgrade to the latest version of Discourse Placeholder Forms as the vulnerability has been addressed in commit a62f711d5600e4e5d86f342d52932cb6221672e7.
What is the impact of CVE-2024-43408?
The impact of CVE-2024-43408 is that it allows for potential XSS attacks through unsanitized user inputs in dynamic documentation.
Which versions of Discourse Placeholder Forms are vulnerable to CVE-2024-43408?
All versions of Discourse Placeholder Forms prior to the fix in commit a62f711d5600e4e5d86f342d52932cb6221672e7 are vulnerable to CVE-2024-43408.
Is user data at risk with CVE-2024-43408?
Yes, user data may be at risk with CVE-2024-43408 due to the potential for XSS attacks stemming from vulnerable unsanitized input.