GHSA-4j38-rw27-97gxMediumCVSS 6.5
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
🔗 CVE IDs covered (1)
📋 Description
Impact
It's possible to forge a request to delete a message.
Patches
The problem has been patched in version 2.0-rc-1 of Discussion Extension.
Workarounds
There's no easy workaround except upgrading.
References
https://jira.xwiki.org/browse/DISCUSSION-22
For more information
If you have any questions or comments about this advisory:
- Open an issue in Jira XWiki
- Email us at security mailing-list
🎯 Affected products1
- maven/org.xwiki.contrib:discussions-server:< 2.0-rc-1