CVE-2023-34089 HIGH

CVE-2023-34089: Decidim Cross-site Scripting vulnerability in the processes filter

Vendor Decidim
Product decidim
Weakness CWE-79 · XSS
Published July 11, 2023
Last update November 4, 2024

CVSS base score

8.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The processes filter feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing. The problem was patched in version 0.27.3 and 0.26.7.

Key dates

02Disclosure timeline

July 11, 2023 CVE published
November 4, 2024 Record updated