Medium severity5.3NVD Advisory· Published Sep 23, 2021· Updated Jun 17, 2026
CVE-2020-24327
CVE-2020-24327
Description
Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
52.3.2 - 2.6+ 3 more
- (no CPE)range: 2.3.2 - 2.6
- cpe:2.3:a:discourse:discourse:2.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:discourse:discourse:2.6.0:-:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
2- github.com/discourse/discourse/pull/10509nvdExploitPatchThird Party Advisory
- github.com/purple-WL/Discourse-sending-email-function-exist-Server-side-request-forgery-SSRF-/issues/1nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.