VDB
Sign up
HIGH7.1

GHSA-7cx8-44pc-xv3q

Decidim cross-site scripting (XSS) in the pagination

Quick fix

GHSA-7cx8-44pc-xv3q — decidim: upgrade to the fixed version with the command below.

bundle update decidim

Details

### Impact

The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter `per_page`.

### Patches

Not available

### Workarounds

Not available

### References

OWASP ASVS v4.0.3-5.1.3

### Credits

This issue was discovered in a security audit organized by the [mitgestalten Partizipationsbüro](https://partizipationsbuero.at/) and funded by [netidee](https://www.netidee.at/) against Decidim done during April 2024. The security audit was implemented by [AIT Austrian Institute of Technology GmbH](https://www.ait.ac.at/),

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/decidim
Introduced in: 0Fixed in: 0.27.6
Fixbundle update decidim
RubyGems/decidim
Introduced in: 0.28.0.rc1Fixed in: 0.28.1
Fixbundle update decidim

References