User Reaction Data Exposure in Discourse-reactions Plugin (Patch: 2c26939)

User Reaction Data Exposure in Discourse-reactions Plugin (Patch: 2c26939)

CVE-2023-49098 · LOW Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability was patched in commit 2c26939.

Learn more about our User Device Pen Test.