Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys. This issue has been patched in version 0.26.8 and 0.27.4.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-2663 Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys. This issue has been patched in version 0.26.8 and 0.27.4.
Github GHSA Github GHSA GHSA-639h-86hw-qcjq Decidim has broken access control in templates
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 19 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-19T18:48:00.313Z

Reserved: 2023-06-21T18:50:41.700Z

Link: CVE-2023-36465

cve-icon Vulnrichment

Updated: 2024-08-02T16:45:57.045Z

cve-icon NVD

Status : Modified

Published: 2023-10-06T12:15:11.683

Modified: 2024-11-21T08:09:46.057

Link: CVE-2023-36465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.