Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*
- <= 3.4.0.beta3
A vulnerability exists in Discourse versions beta through 3.4.0.beta3 and in the 'tests-passed' version range through 3.4.0.beta3. This issue allows an attacker to manipulate a user's username by sending a carefully crafted link that exploits the 'activate-account' route. The vulnerability requires user interaction to be exploited.
Exploitation of this vulnerability allows for unauthorized changes to a user's username.
Users are advised to upgrade to Discourse version 3.4.0.beta4 or later. Instructions for upgrading can be found in the Discourse documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.