Vulnerability Description
Decidim is a participatory democracy framework. The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter `per_page`. This vulnerability is fixed in 0.27.6 and 0.28.1.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/decidim/decidim/releases/tag/v0.27.6
- https://github.com/decidim/decidim/releases/tag/v0.28.1
- https://github.com/decidim/decidim/security/advisories/GHSA-7cx8-44pc-xv3q
- https://github.com/decidim/decidim/releases/tag/v0.27.6
- https://github.com/decidim/decidim/releases/tag/v0.28.1
- https://github.com/decidim/decidim/security/advisories/GHSA-7cx8-44pc-xv3q
FAQ
What is CVE-2024-32469?
CVE-2024-32469 is a vulnerability with a CVSS score of 7.1 (HIGH). Decidim is a participatory democracy framework. The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter `per_page`. This ...
How severe is CVE-2024-32469?
CVE-2024-32469 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-32469?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.