A medium-severity Cross-Site Request Forgery (CSRF) vulnerability, tracked as CVE-2023-37465 with a CVSS score of 6.5, has been identified in the org.xwiki.contrib:discussions-server package. This flaw allows an attacker to delete messages by forging a request through user interaction, potentially impacting integrity via environment template management API. The attack vector is network-based (AV:N), and the attack complexity is low (AC:L). User interaction is required for exploitation (UI:R), but no sensitive data can be accessed or compromised (C:N). However, integrity of the system may be impacted (I:H). This vulnerability affects versions prior to 2.0-rc-1.
We recommend you to update org.xwiki.contrib:discussions-server to version 2.0-rc-1.[/subscribe_to_unlock_form]
A medium-severity Cross-Site Request Forgery (CSRF) vulnerability, tracked as CVE-2023-37465 with a CVSS score of 6.5, has been identified in the org.xwiki.contrib:discussions-server package. This flaw allows an attacker to delete messages by forging a request through user interaction, potentially impacting integrity via environment template management API. The attack vector is network-based (AV:N), and the attack complexity is low (AC:L). User interaction is required for exploitation (UI:R), but no sensitive data can be accessed or compromised (C:N). However, integrity of the system may be impacted (I:H). This vulnerability affects versions prior to 2.0-rc-1.
We recommend you to update org.xwiki.contrib:discussions-server to version 2.0-rc-1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]