5.4 CVE-2025-54411

Patch
 

Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable to XSS attacks, which affect the user themselves or an admin impersonating them. Admins can temporarily alter the welcome_banner.header.logged_in_members site text to remove the preferred_display_name placeholder, or not impersonate any users for the time being. This vulnerability is fixed in 3.5.0.beta8.
https://nvd.nist.gov/vuln/detail/CVE-2025-54411

Categories

CWE-79

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:* < 3.5.0
cpe:2.3:a:discourse:discourse:3.5.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta2:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta3:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta4:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta5:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta6:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.5.0:beta7:*:*:beta:*:*:*


REMEDIATION


Patch

Url
https://github.com/discourse/discourse/commit/a3374d2850f07444d113216e1d539ee...


EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry