Intelligence View
CVE-2025-48954 | Discourse up to 3.5.0.beta5 Content Security Policy cross site scripting (GHSA-26p5-mjjh-wfcf)
A vulnerability has been found in Discourse up to 3.5.0.beta5 and classified as problematic. This vulnerability affects unknown code of the component Content Security Policy Handler. This manipulation causes cross site scripting. This…
This vulnerability is registered as CVE-2025-48954. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
2. Cyber Threat Intelligence & Forensik
3. Compliance, SLA & Vendor Adherence
Hersteller-Sicherheitsmeldungen & Patch-Status
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com