CVE-2023-2850
MEDIUMNodeBB - CSRF
Title source: llmDescription
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.
Scores
CVSS v3
4.7
EPSS
0.0013
EPSS Percentile
31.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Classification
CWE
CWE-346
CWE-1385
Status
published
Affected Products (2)
nodebb/nodebb
< 2.8.13
npm/nodebb
< 3.1.3npm
Timeline
Published
Jul 25, 2023
Tracked Since
Feb 18, 2026