Impact
Decidim is a participatory democracy framework. A vulnerability in the /admin/csv_census/census_logs record‑management endpoints allows a user with the participant manager role to create, modify, or delete Decidim::Verifications::CsvDatum records without proper administrator authorization, resulting in unauthorized data manipulation and potential exposure of demographic information.
Affected Systems
The flaw exists in Decidim releases prior to 0.30.9, from 0.31.0 up to but excluding 0.31.5, and in 0.32.0.rc1 up until but excluding 0.32.0.rc2. Administrators using those versions are affected.
Risk and Exploitability
The CVSS score is 6, indicating moderate severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. Because the flaw requires only a participant manager role, an attacker who can elevate privileges or obtain a participant manager account can exploit the endpoints via HTTP requests, representing a moderate risk for unpatched Decidim deployments.
OpenCVE Enrichment
Github GHSA