Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.28.3 and 0.29.0.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3271 | Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.28.3 and 0.29.0. |
Github GHSA |
GHSA-j4h6-gcj7-7v9v | decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embeds |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 13 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Decidim
Decidim decidim |
|
| CPEs | cpe:2.3:a:decidim:decidim:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Decidim
Decidim decidim |
|
| Metrics |
ssvc
|
Wed, 13 Nov 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.28.3 and 0.29.0. | |
| Title | Decidim allows cross-site scripting (XSS) in the online or hybrid meeting embeds | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-13T18:43:57.042Z
Reserved: 2024-09-02T16:00:02.423Z
Link: CVE-2024-45594
Updated: 2024-11-13T18:43:33.960Z
Status : Awaiting Analysis
Published: 2024-11-13T17:15:10.333
Modified: 2024-11-15T14:00:09.720
Link: CVE-2024-45594
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA