Skip to content

Arbitrary HTML injection in discourse-mermaid-theme-component

Moderate
jomaxro published GHSA-8437-hgcm-p3q3 Jan 4, 2023

Package

discourse-mermaid-theme-component (Discourse)

Affected versions

1.0.0

Patched versions

1.1.0

Description

Impact

Users that can create posts are able to inject arbitrary HTML on that post.

Patches

The issue has been fixed on the main branch. Admins can update the theme component through the admin UI (Customize -> Themes -> Components -> discourse-mermaid-theme-component -> Check for Updates)

Workarounds

Alternatively, admins can temporarily disable discourse-mermaid-theme-component.

Severity

Moderate
5.0
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CVE ID

CVE-2022-46180

Weaknesses

No CWEs

Credits