ZeroHour

CVE-2023-2850

CVSS 3.1
4.7 medium
EPSS
<1%p26
Published
()
Modified
Description

NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.

Vendors
nodebb
Products
nodebb
Weakness
CWE-1385, CWE-346
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.