CVE-2023-45131
HIGHDiscourse < 3.1.1 - Unauthenticated Exposure of Sensitive Information via MessageBus
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2023-45131. PoCs published by İbrahimsql, ibrahmsql.
AI-analyzed exploit summary This Ruby script exploits CVE-2023-45131, an unauthenticated access vulnerability in Discourse's MessageBus, allowing enumeration of chat channels, interception of private messages, and real-time monitoring of communications. It demonstrates multiple attack vectors including channel enumeration and message history access.
Description
Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Exploits (2)
This Ruby script exploits CVE-2023-45131, an unauthenticated access vulnerability in Discourse's MessageBus, allowing enumeration of chat channels, interception of private messages, and real-time monitoring of communications. It demonstrates multiple attack vectors including channel enumeration and message history access.
The repository contains a functional Ruby exploit for CVE-2023-45131, which allows unauthenticated access to private chat messages in Discourse via the MessageBus endpoint. The PoC demonstrates enumeration of chat channels, interception of private messages, and real-time monitoring.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N