← Back

CVE-2024-39320

nvd nist
Published: Jul 30, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.

Affected (5)

Products: Discourse: Discourse
1 product
Discourse
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Discourse
Before 3.2.5
Version 3.3.0 beta1
Version 3.3.0 beta2
Version 3.3.0 beta3
Version 3.3.0 beta4

Timeline

No history available yet.