Headline
GHSA-7cx8-44pc-xv3q: Decidim cross-site scripting (XSS) in the pagination
Impact
The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter per_page
.
Patches
Patched in version 0.27.6 and 0.28.1
References
OWASP ASVS v4.0.3-5.1.3
Credits
This issue was discovered in a security audit organized by the mitgestalten Partizipationsbüro and funded by netidee against Decidim done during April 2024. The security audit was implemented by AIT Austrian Institute of Technology GmbH,
Decidim cross-site scripting (XSS) in the pagination
High severity GitHub Reviewed Published Jul 10, 2024 in decidim/decidim • Updated Jul 10, 2024