Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-47773 PoC — Anonymous cache poisoning via XHR requests in Discourse

Source
Associated Vulnerability
Title:Anonymous cache poisoning via XHR requests in Discourse (CVE-2024-47773)
Description:Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value.
Readme
# CVE-2024-47773
File Snapshot

[4.0K] /data/pocs/b38ff5f8ee16fa032048f73d067937e8329fe878 ├── [9.0K] CVE-2024-47773.py ├── [ 34K] LICENSE └── [ 16] README.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →