Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7cx8-44pc-xv3q

Опубликовано: 10 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.3
CVSS3: 7.1

Описание

Decidim cross-site scripting (XSS) in the pagination

Impact

The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter per_page.

Patches

Not available

Workarounds

Not available

References

OWASP ASVS v4.0.3-5.1.3

Credits

This issue was discovered in a security audit organized by the mitgestalten Partizipationsbüro and funded by netidee against Decidim done during April 2024. The security audit was implemented by AIT Austrian Institute of Technology GmbH,

Пакеты

Наименование

decidim

rubygems
Затронутые версииВерсия исправления

< 0.27.6

0.27.6

Наименование

decidim

rubygems
Затронутые версииВерсия исправления

>= 0.28.0.rc1, < 0.28.1

0.28.1

EPSS

Процентиль: 65%
0.00485
Низкий

6.3 Medium

CVSS4

7.1 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.1
nvd
больше 1 года назад

Decidim is a participatory democracy framework. The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter `per_page`. This vulnerability is fixed in 0.27.6 and 0.28.1.

EPSS

Процентиль: 65%
0.00485
Низкий

6.3 Medium

CVSS4

7.1 High

CVSS3

Дефекты

CWE-79