GHSA-4j38-rw27-97gx

Suggest an improvement
Source
https://github.com/advisories/GHSA-4j38-rw27-97gx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4j38-rw27-97gx/GHSA-4j38-rw27-97gx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4j38-rw27-97gx
Aliases
  • CVE-2023-37465
Published
2026-07-27T17:04:00Z
Modified
2026-07-27T17:15:31.109170258Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
Details

Impact

It's possible to forge a request to delete a message.

Patches

The problem has been patched in version 2.0-rc-1 of Discussion Extension.

Workarounds

There's no easy workaround except upgrading.

References

https://jira.xwiki.org/browse/DISCUSSION-22

For more information

If you have any questions or comments about this advisory: * Open an issue in Jira XWiki * Email us at security mailing-list

Database specific
{
    "cwe_ids": [
        "CWE-352"
    ],
    "github_reviewed_at": "2026-07-27T17:04:00Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "nvd_published_at": null
}
References

Affected packages

Maven / org.xwiki.contrib:discussions-server

Package

Name
org.xwiki.contrib:discussions-server
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.contrib/discussions-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0-rc-1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4j38-rw27-97gx/GHSA-4j38-rw27-97gx.json"