Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2021-43786

Disclosure Date: November 29, 2021 (last updated February 23, 2025)
Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API. The vulnerability has been patch as of v1.18.5. Users are advised to upgrade as soon as possible.
Attacker Value
Unknown

CVE-2020-15149

Disclosure Date: August 20, 2020 (last updated February 22, 2025)
NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could lead to a privilege escalation event due via an account takeover. As a workaround you may cherry-pick the following commit from the project's repository to your running instance of NodeBB: 16cee1b03ba3eee177834a1fdac4aa8a12b39d2a. This is fixed in version 1.14.3.
Attacker Value
Unknown

CVE-2015-9286

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
0
Attacker Value
Unknown

CVE-2015-3296

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript: or (2) data: URLs.
0