CVE-2022-39270 Information
Description
DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component’s settings) are able to inject arbitrary HTML on that topic’s page. The issue has been fixed on the main branch. Admins can update the theme component through the admin UI (Customize -> Themes -> Components -> DiscoTOC -> Check for Updates). Alternatively admins can temporarily disable the DiscoTOC theme component.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/discourse/DiscoTOC/commit/f80c215a283cd045d2a371403e6eba88b2911192 https://github.com/discourse/DiscoTOC/security/advisories/GHSA-m44p-w923-w32h
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: