CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-4j38-rw27-97gx: org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages

mediumCVSS 6.5CVE-2023-37465
Impact It's possible to forge a request to delete a message. Patches The problem has been patched in version 2.0-rc-1 of Discussion Extension. Workarounds There's no easy workaround except upgrading. References https://jira.xwiki.org/browse/DISCUSSION-22 For more information If you have any questions or comments about this advisory: - Open an issue in Jira XWiki - Email us at security mailing-list

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium — CVSS 6.5
Published
2026-07-27
Last updated
2026-07-27
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-4j38-rw27-97gx

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2023-37465coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories