CVE-2025-22601
CVSS 3.1 Score 3.1 of 10 (low)
Details
Published Feb 4, 2025
CWE ID 22
Summary
CVE-2025-22601 is a vulnerability affecting Discourse, an open-source platform for community discussions. Maliciously crafted links through the `activate-account` route can manipulate users into making changes to their own usernames. This issue, which allows attackers to exploit the trust of users, has been addressed in the latest version of Discourse. Users are strongly encouraged to upgrade as soon as possible, as there are currently no known workarounds to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Discourse