Decidim Cross-site Scripting vulnerability in the external link redirections
Published: July 11, 2023
SECURITY IDENTIFIERS
- CVE: CVE-2023-32693 (NVD)
- GHSA: GHSA-469h-mqg8-535r
- Vendor Advisory: https://github.com/decidim/decidim/security/advisories/GHSA-469h-mqg8-535r
GEM
SEVERITY
CVSS v3.x: 8.1 (High)
UNAFFECTED VERSIONS
< 0.25.0
PATCHED VERSIONS
~> 0.26.6
>= 0.27.3
DESCRIPTION
Impact
The external link feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing.
