PT-2024-24596 · Decidim · Decidim

Patrick Himler

·

Published

2024-07-10

·

Updated

2024-07-11

·

CVE-2024-32469

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Decidim versions prior to 0.27.6 Decidim versions prior to 0.28.1
Description The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter per page. This issue was discovered in a security audit organized by the mitgestalten Partizipationsbüro and funded by netidee against Decidim done during April 2024.
Recommendations For Decidim versions prior to 0.27.6, update to version 0.27.6 or later to fix the vulnerability. For Decidim versions prior to 0.28.1, update to version 0.28.1 or later to fix the vulnerability. As a temporary workaround, consider restricting access to the per page parameter in the affected API endpoint until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-32469
GHSA-7CX8-44PC-XV3Q

Affected Products

Decidim