PT-2024-31696 · Decidim · Decidim

Whotwagner

·

Published

2024-11-13

·

Updated

2024-11-15

·

CVE-2024-45594

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Decidim versions prior to 0.28.3 Decidim versions prior to 0.29.0
Description: Decidim is a participatory democracy framework. The meeting embeds feature used in online or hybrid meetings is subject to potential XSS attack through a malformed URL.
Recommendations: For versions prior to 0.28.3, update to version 0.28.3 or later. For versions prior to 0.29.0, update to version 0.29.0 or later. As a temporary workaround, consider disabling the creation of meetings by participants in the meeting component until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45594
GHSA-J4H6-GCJ7-7V9V

Affected Products

Decidim