Skip to content

XSS due to lack of CSRF validation for replying/publishing

Moderate
psychobunny published GHSA-43m5-c88r-cjvv Aug 25, 2020

Package

npm nodebb-plugin-blog-comments (npm)

Affected versions

< 0.7.0

Patched versions

0.7.0

Description

Impact

Due to lack of CSRF validation, a logged in user is potentially vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum.

Patches

Upgrade to the latest version v0.7.0

Workarounds

You can cherry-pick the following commit: cf43bee

References

Visit https://community.nodebb.org if you have any questions about this issue or on how to patch / upgrade your instance.

Severity

Moderate

CVE ID

CVE-2020-15156

Weaknesses

No CWEs

Credits