CVE-2023-2850

Publication date

2023-07-25 11:13:18

Family

snyk

State

PUBLISHED

Description

NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.