VYPR
Unrated severityNVD Advisory· Published Jan 5, 2023· Updated Mar 10, 2025

Discourse vulnerable to private topic leak via email#send_digest

CVE-2022-23546

Description

In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's digest of recent topics, possibly exposing private information. A patch is available for version 2.9.0.beta15. There are no known workarounds for this issue.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.