Impact
An administrator with landing‑page editing privileges in Decidim can store arbitrary HTML and JavaScript in an HTML content block, which is rendered without sanitization. A visitor that loads the landing page receives the injected script in their browser, enabling a stored cross‑site scripting attack.
Affected Systems
Decidim versions prior to 0.30.9, 0.31.5, and 0.32.0.rc2 are impacted. Affected builds include 0.30.x before 0.30.9, 0.31.x before 0.31.5, and the first release candidate 0.32.0.rc1 before 0.32.0.rc2. The vulnerability exists in the Decidim participatory democracy framework supplied by the vendor decidim:decidim.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate risk; the EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires an administrator with editing rights, making it an internal privilege misuse or compromise of an administrator account. Once the malicious content block is created, it is served to every visitor, making exploitation trivial once the initial privilege is granted. No external network access or privilege escalation is required.
OpenCVE Enrichment
Github GHSA