CVE-2024-57041
PoC moderateStored XSS in NodeBB 3.11.0 via profile 'About Me' field
NodeBB forum software v3.11.0 contains a persistent (stored) cross-site scripting vulnerability (CWE-79) in the 'About Me' section of user profiles. A remote authenticated user can save arbitrary script or markup in their own profile, and the payload executes in the browsers of other users — including moderators and administrators — whenever they view that profile. Successful exploitation lets the attacker run JavaScript in the victim's session, enabling actions such as cookie theft or performing actions on the victim's behalf; the CVSS 3.1 score of 4.6 (medium) reflects limited confidentiality/integrity impact and the required user interaction. Any NodeBB community running v3.11.0 is affected per the advisory, though the data does not specify whether other versions are impacted. A public proof of concept has been published, the issue is not in CISA's KEV, and EPSS assigns a 39.3% probability of exploitation within 30 days (99th percentile), so defenders should treat this as a realistic near-term threat.
What to do: Upgrade NodeBB to a release newer than v3.11.0 once a patched version is available, and monitor the vendor's releases for the official fix. As interim mitigation, disable or restrict the profile 'About Me' field (or sanitize its HTML) and have administrators review existing profiles for injected scripts or links. Because injection requires an account, prioritize reviewing recently registered or low-trust user profiles.
| NodeBB | v3.11.0 (as reported; other versions not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.
- Vendors
- nodebb
- Products
- nodebb
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.