NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
ID: bdd15d96-5016-56de-bfc4-cace9c734d46
STIX ID: report--bdd15d96-5016-56de-bfc4-cace9c734d46
Feed Name: The Hacker News
Eight high-severity vulnerabilities in NodeBB forum software (affecting versions before 4.14.0) were publicly disclosed along with exploit code; issues include an admin-dashboard settings bypass, account impersonation and private-message disclosure, widespread XSS enabling attacker-supplied links to execute code, post takeover and vote inflation, and multiple federation-related attacks. Many flaws stem from inconsistent access checks and several live in the federation code (which may be enabled by default on fresh installs). NodeBB has released fixes through 4.14.0–4.14.2 and administrators are advised to upgrade and review themes/plugins because template handling changed, although the report says no active exploitation or CVE assignments for these eight were reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
