VDB
Sign up
MEDIUM6.1

GHSA-469h-mqg8-535r

Decidim Cross-site Scripting vulnerability in the external link redirections

Quick fix

GHSA-469h-mqg8-535r — decidim: upgrade to the fixed version with the command below.

bundle update decidim

Details

### Impact

The external link feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing.

### Patches

The problem was patched in [v0.27.3](https://github.com/decidim/decidim/releases/tag/v0.27.3) and [v0.26.7](https://github.com/decidim/decidim/releases/tag/v0.26.7)

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/decidim
Introduced in: 0.25.0Fixed in: 0.26.7
Fixbundle update decidim
RubyGems/decidim-core
Introduced in: 0.27.0Fixed in: 0.27.3
Fixbundle update decidim-core
RubyGems/decidim-core
Introduced in: 0.25.0Fixed in: 0.26.7
Fixbundle update decidim-core
RubyGems/decidim
Introduced in: 0.27.0Fixed in: 0.27.3
Fixbundle update decidim

References