CVE-2022-46148 describes a self-XSS vulnerability in Discourse versions 2.8.10 and prior (stable branch) and 2.9.0.beta11 and prior (beta/tests-passed branches). Malicious messages could trigger a full XSS on sites with modified or disabled Content Security Policy when a user navigates to their drafts page. The vulnerability has a CVSS score of 5.4 (MEDIUM), indicating a network-based attack with low complexity requiring user interaction and low privileges, potentially impacting confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting low current exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.8.10CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* | ||
2.9.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:2.9.0:beta1:*:*:*:*:*:* | ||
2.9.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:2.9.0:beta10:*:*:*:*:*:* | ||
2.9.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:2.9.0:beta11:*:*:*:*:*:* | ||
2.9.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:2.9.0:beta2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.