Feed/CVE-2023-37465
CVE-2023-37465MEDIUMCVSS 6.5

org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages

Published Jul 27, 2026·Updated Jul 27, 2026

NVD Description

### Impact It's possible to forge a request to delete a message. ### Patches The problem has been patched in version 2.0-rc-1 of Discussion Extension. ### Workarounds There's no easy workaround except upgrading. ### References https://jira.xwiki.org/browse/DISCUSSION-22 ### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki](https://jira.xwiki.org) * Email us at [security mailing-list](mailto:security@xwiki.org)

Affected Packages (1)

org.xwiki.contrib:discussions-serverMAVEN
Fixed in 2.0-rc-1

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free