CVE-2024-56328

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 4, 2025
CWE ID 79

Summary

CVE-2024-56328 is a vulnerability affecting Discourse, an open-source community discussion platform. An attacker can exploit this issue by posting a specially crafted onebox URL, leading to the execution of arbitrary JavaScript on users' browsers. This vulnerability only poses a threat to sites with Content Security Policy (CSP) disabled. Discourse has released a patch for this issue in its latest version. Users who cannot upgrade immediately should enable CSP, disable inline Oneboxes globally, or allow specific domains for Oneboxing to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share