Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rx9f-5ggv-5rh6

Опубликовано: 16 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6
CVSS3: 6.8

Описание

Decidim::Admin vulnerable to cross-site scripting (XSS) in the admin activity log

Impact

The admin panel is subject to potential XSS attach in case an admin assigns a valuator to a proposal, or does any other action that generates an admin activity log where one of the resources has an XSS crafted.

Patches

N/A

Workarounds

Redirect the pages /admin and /admin/logs to other admin pages to prevent this access (i.e. /admin/organization/edit)

References

OWASP ASVS v4.0.3-5.1.3

Пакеты

Наименование

decidim-admin

rubygems
Затронутые версииВерсия исправления

<= 0.27.6

0.27.7

Наименование

decidim-admin

rubygems
Затронутые версииВерсия исправления

>= 0.28.0, <= 0.28.1

0.28.2

EPSS

Процентиль: 68%
0.00567
Низкий

6 Medium

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.8
nvd
больше 1 года назад

decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The admin panel is subject to potential Cross-site scripting (XSS) attach in case an admin assigns a valuator to a proposal, or does any other action that generates an admin activity log where one of the resources has an XSS crafted. This issue has been addressed in release version 0.27.7, 0.28.2, and newer. Users are advised to upgrade. Users unable to upgrade may redirect the pages /admin and /admin/logs to other admin pages to prevent this access (i.e. `/admin/organization/edit`).

EPSS

Процентиль: 68%
0.00567
Низкий

6 Medium

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-79