← Back to CVE List

CVE-2024-39320

Published: 2024-07-30T15:15Z
Last Modified: 2024-11-21T09:27Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt