Skip to content

Arbitrary HTML injection in table-of-contents theme component

Moderate
jomaxro published GHSA-m44p-w923-w32h Oct 3, 2022

Package

DiscoTOC (Discourse)

Affected versions

< 2.1.0

Patched versions

>= 2.1.0

Description

Impact

Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component's settings) are able to inject arbitrary HTML on that topic's page.

Patches

The issue has been fixed on the main branch. Admins can update the theme component through the admin UI (Customize -> Themes -> Components -> DiscoTOC -> Check for Updates)

Workarounds

Alternatively, admins can temporarily disable the DiscoTOC theme component.

Severity

Moderate

CVE ID

CVE-2022-39270

Weaknesses

No CWEs