Impact
Decidim, a participatory democracy framework, contains a flaw in versions prior to 0.32.0 that allows a process‑scoped administrator or election editor with question‑management rights to store arbitrary HTML or script code in the question.body field. The question_title helper renders this content with html_safe and no sanitization, resulting in stored script execution when any visitor opens a public election page or voting booth screen. The injected script runs in the browser of anyone who views the election, giving the attacker a client‑side foothold, session hijacking or other browser‑based attacks, as defined by CWE‑79.
Affected Systems
The vulnerability exists in the Decidim participatory‑democracy framework in all releases earlier than 0.32.0 for users holding process‑scoped administrator or election editor roles that can manage question titles.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact; the EPSS score is < 1% and the flaw is not listed in CISA KEV. Because the attack requires only application‑level permissions that are normally granted to election editors, an internal attacker could easily inject malicious content. Once injected, the script runs unconditionally for every visitor, giving the attacker persistent, client‑side foothold.
OpenCVE Enrichment
Github GHSA