CVE-2022-39270
Dashboard / Vulnerabilities / CVE-2022-39270
Summary: Arbitrary HTML injection in table-of-contents theme component in DiscoTOC
Details: DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component's settings) are able to inject arbitrary HTML on that topic's page. The issue has been fixed on the `main` branch. Admins can update the theme component through the admin UI (Customize -> Themes -> Components -> DiscoTOC -> Check for Updates). Alternatively, admins can temporarily disable the DiscoTOC theme component.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39270.json, https://github.com/discourse/DiscoTOC/security/advisories/GHSA-m44p-w923-w32h, https://nvd.nist.gov/vuln/detail/CVE-2022-39270, https://github.com/discourse/DiscoTOC/commit/f80c215a283cd045d2a371403e6eba88b2911192
Affected packages
Package
Name:
Purl:
