Vulnerabilities/

XSS due to lack of CSRF validation for replying/publishing

Severity:
Medium

Description

Due to lack of CSRF validation, a logged in user is potentially vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum.

Recommendation

Update the nodebb-plugin-blog-comments package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
nodebb-plugin-blog-comments
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing