CVE-2024-43408 - CVE House
Back to Database
Status published Medium CVE-2024-43408

Discourse Placeholder Forms has a XSS stopped by CSP

Vulnerability Description

Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in the html of the post. The vulnerability is fixed in commit a62f711d5600e4e5d86f342d52932cb6221672e7.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-43408

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

discourse-placeholder-theme-component
Vulnerable Versions:
< a62f711d5600e4e5d86f342d52932cb6221672e7

Timeline

Official Publish: August 20th, 2024
Last Modified: September 3rd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Weaknesses (CWE)