NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.
The product does not properly verify that the source of data or communication is valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nodebb | Nodebb | * | 2.8.13 (excluding) |
Nodebb | Nodebb | 3.0.0 (including) | 3.1.3 (excluding) |