Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2021-43786
Disclosure Date: November 29, 2021 (last updated February 23, 2025)
Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API. The vulnerability has been patch as of v1.18.5. Users are advised to upgrade as soon as possible.
0
Attacker Value
Unknown
CVE-2020-15149
Disclosure Date: August 20, 2020 (last updated February 22, 2025)
NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could lead to a privilege escalation event due via an account takeover. As a workaround you may cherry-pick the following commit from the project's repository to your running instance of NodeBB: 16cee1b03ba3eee177834a1fdac4aa8a12b39d2a. This is fixed in version 1.14.3.
0
Attacker Value
Unknown
CVE-2015-9286
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
0
Attacker Value
Unknown
CVE-2015-3296
Disclosure Date: September 21, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript: or (2) data: URLs.
0