GHSA-43m5-c88r-cjvv

Suggest an improvement
Source
https://github.com/advisories/GHSA-43m5-c88r-cjvv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-43m5-c88r-cjvv/GHSA-43m5-c88r-cjvv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-43m5-c88r-cjvv
Aliases
Published
2020-08-26T18:55:38Z
Modified
2026-07-08T06:00:33Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
XSS due to lack of CSRF validation for replying/publishing
Details

Impact

Due to lack of CSRF validation, a logged in user is potentially vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum.

Patches

Upgrade to the latest version v0.7.0

Workarounds

You can cherry-pick the following commit: https://github.com/psychobunny/nodebb-plugin-blog-comments/commit/cf43beedb05131937ef46f365ab0a0c6fa6ac618

References

Visit https://community.nodebb.org if you have any questions about this issue or on how to patch / upgrade your instance.

Database specific
{
    "cwe_ids":  [
        "CWE-352"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-26T18:55:19Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / nodebb-plugin-blog-comments

Package

Name
nodebb-plugin-blog-comments
View open source insights on deps.dev
Purl
pkg:npm/nodebb-plugin-blog-comments

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.7.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-43m5-c88r-cjvv/GHSA-43m5-c88r-cjvv.json"