peter bassill · operator
$ cve CVE-2023-45131 JSON

CVE-2023-45131 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 1.8% (pctl 78)

Patch early

A public exploit exists.

Description

Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS1.81% — more likely to be exploited than 78% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2023-10-16
Last modified2026-06-17

Affected (1)

VendorProduct
discoursediscourse

Public exploits

SourceTitleDate
exploit-dbDiscourse 3.1.1 - Unauthenticated Chat Message Access2025-07-22

References

→ the Explorer  ·  watch your stack  ·  NVD