CVE-2026-72725
Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that could inject stored cross-site scripting into the staff interface. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
वीकनेस
Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that could inject stored cross-site scripting into the staff interface. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
संदर्भ
- https://github.com/discourse/discourse/commit/66601a6e6eeeabfcb06d2f692d68534be12de082
- https://github.com/discourse/discourse/commit/74ae22d85f4e13c7c7f2e3c13fce023feec7e033
- https://github.com/discourse/discourse/commit/fd44510b4303e7f8f0b42bd070a2d42d3cda259f
- https://github.com/discourse/discourse/security/advisories/GHSA-8x29-vv56-wj6v
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।