Impact
Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component's settings) are able to inject arbitrary HTML on that topic's page.
Patches
The issue has been fixed on the main
branch. Admins can update the theme component through the admin UI (Customize -> Themes -> Components -> DiscoTOC -> Check for Updates)
Workarounds
Alternatively, admins can temporarily disable the DiscoTOC theme component.
Impact
Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component's settings) are able to inject arbitrary HTML on that topic's page.
Patches
The issue has been fixed on the
main
branch. Admins can update the theme component through the admin UI (Customize -> Themes -> Components -> DiscoTOC -> Check for Updates)Workarounds
Alternatively, admins can temporarily disable the DiscoTOC theme component.