PT-2024-24596 · Decidim · Decidim
Patrick Himler
·
Published
2024-07-10
·
Updated
2024-07-11
·
CVE-2024-32469
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Decidim versions prior to 0.27.6
Decidim versions prior to 0.28.1
Description
The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter
per page. This issue was discovered in a security audit organized by the mitgestalten Partizipationsbüro and funded by netidee against Decidim done during April 2024.Recommendations
For Decidim versions prior to 0.27.6, update to version 0.27.6 or later to fix the vulnerability.
For Decidim versions prior to 0.28.1, update to version 0.28.1 or later to fix the vulnerability.
As a temporary workaround, consider restricting access to the
per page parameter in the affected API endpoint until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Decidim