CVE-2022-23549

MEDIUM

Discourse < 2.8.14 - Input Validation Bypass via HTML Comments

Title source: llm
STIX 2.1

Description

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, users can create posts with raw body longer than the `max_length` site setting by including html comments that are not counted toward the character limit. This issue is patched in versions 2.8.14 and 2.9.0.beta16. There are no known workarounds.

Scores

CVSS v3 5.7
EPSS 0.0057
EPSS Percentile 42.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (3)
discourse/discourse 2.9.0 beta1 (13 CPE variants)
discourse/discourse 3.0.0 beta15
discourse/discourse < 2.8.14
Published Jan 05, 2023
Tracked Since Feb 18, 2026