Vulnerability Details
Basic Information
| Title | CVE-2025-46824 |
|---|---|
| Type | cve |
| Published | 2025-05-07T18:15:42 |
| Last Seen | 2025-05-07T18:24:32 |
| CVSS Score | 3.1 (LOW) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | HIGH |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | LOW |
| Integrity Impact | NONE |
| Availability Impact | NONE |
CVE Information
| CVE IDs | CVE-2025-46824 |
|---|---|
| CWE | CWE-79 |
| Bulletin Family | cve |
Description
The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This…
Impact Assessment
| Base Score | 3.1 |
|---|---|
| Severity | LOW |