Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Fri, 20 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Dec 2024 19:30:00 +0000

Type Values Removed Values Added
Description Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Magnific lightbox susceptible to Cross-site Scripting in Discourse
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-12-19T19:12:29.589Z

Updated: 2024-12-20T20:42:25.778Z

Reserved: 2024-11-15T17:11:13.439Z

Link: CVE-2024-52794

cve-icon Vulnrichment

Updated: 2024-12-20T20:42:22.501Z

cve-icon NVD

Status : Received

Published: 2024-12-19T20:15:07.513

Modified: 2024-12-19T20:15:07.513

Link: CVE-2024-52794

cve-icon Redhat

No data.