GHSA-7cx8-44pc-xv3q
Decidim cross-site scripting (XSS) in the pagination
Quick fix
GHSA-7cx8-44pc-xv3q — decidim: upgrade to the fixed version with the command below.
bundle update decidimDetails
### Impact
The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter `per_page`.
### Patches
Not available
### Workarounds
Not available
### References
OWASP ASVS v4.0.3-5.1.3
### Credits
This issue was discovered in a security audit organized by the [mitgestalten Partizipationsbüro](https://partizipationsbuero.at/) and funded by [netidee](https://www.netidee.at/) against Decidim done during April 2024. The security audit was implemented by [AIT Austrian Institute of Technology GmbH](https://www.ait.ac.at/),
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/decidim/decidim/security/advisories/GHSA-7cx8-44pc-xv3q[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-32469[ADVISORY]
- https://github.com/decidim/decidim[PACKAGE]
- https://github.com/decidim/decidim/releases/tag/v0.27.6[WEB]
- https://github.com/decidim/decidim/releases/tag/v0.28.1[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/decidim/CVE-2024-32469.yml[WEB]