#VU98057 Improper access control in Discourse - CVE-2024-45051
Published: October 7, 2024
Discourse
Civilized Discourse Construction Kit, Inc.
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper email address validation within encoded email addresses. A remote attacker can use specially crafted email address bypass domain-based restrictions and gain access to private sites, categories and/or groups.