Launch Week Day 1: Announcing Security Design Review
HIGH 7.1 RubyGems

Decidim cross-site scripting (XSS) in the pagination

GHSA-7cx8-44pc-xv3q · CVE-2024-32469

Published · Modified

Description

Impact

The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter per_page.

Patches

Not available

Workarounds

Not available

References

OWASP ASVS v4.0.3-5.1.3

Credits

This issue was discovered in a security audit organized by the mitgestalten Partizipationsbüro and funded by netidee against Decidim done during April 2024. The security audit was implemented by AIT Austrian Institute of Technology GmbH,

Ready to move

Start Securing

Free, no credit card | First findings in minutes