← Back to CVE List

CVE-2022-39279

Published: 2022-10-06T20:15Z
Last Modified: 2024-11-21T07:17Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some places render a chat channel's name and description in an unsafe way, allowing staff members to cause an cross site scripting (XSS) attack by inserting unsafe HTML into them. Version 0.9 has addressed this issue. Users are advised to upgrade. There are no known workarounds for this issue. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt