Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4h6-gcj7-7v9v

Опубликовано: 13 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 7.7

Описание

decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embeds

Impact

The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL.

Patches

Not available

Workarounds

Disable the creation of meetings by participants in the meeting component.

References

OWASP ASVS v4.0.3-5.1.3

Credits

This issue was discovered in a security audit organized by mitgestalten Partizipationsbüro against Decidim. The security audit was implemented by the Austrian Institute of Technology.

Пакеты

Наименование

decidim-meetings

rubygems
Затронутые версииВерсия исправления

>= 0.28.0, < 0.28.3

0.28.3

EPSS

Процентиль: 43%
0.00211
Низкий

5.1 Medium

CVSS4

7.7 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.7
nvd
около 1 года назад

Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.28.3 and 0.29.0.

EPSS

Процентиль: 43%
0.00211
Низкий

5.1 Medium

CVSS4

7.7 High

CVSS3

Дефекты

CWE-79