← Back to CVE List

CVE-2020-15156

Published: 2020-08-26T19:15Z
Last Modified: 2024-11-21T05:04Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt