Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| discourse | discourse-calendar | < 97883109 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-43659 | 8.0 HIGH | Cross-site Scripting via email preview when CSP disabled in Discourse |
| CVE-2023-45131 | 7.5 HIGH | Unauthenticated access to new private chat messages in Discourse |
| CVE-2023-44388 | 7.5 HIGH | Malicious requests can fill up the log files resulting in a deinal of service in Discourse |
| CVE-2023-44391 | 5.3 MEDIUM | Prevent unauthorized access to summary details in Discourse |
| CVE-2023-45147 | 4.9 MEDIUM | Arbitrary keys can be added to a topic's custom fields by any user in Discourse |
| CVE-2023-43814 | 3.7 LOW | Exposure of poll options and votes to unauthorized users in Discourse |
No comments yet