A vulnerability was found in Discourse up to 3.1.3/3.2.0.beta3. It has been classified as critical. Affected is an unknown function of the component Secure Upload URL Handler. The manipulation leads to improper access controls.

This vulnerability is traded as CVE-2023-49099. It is possible to launch the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.