VulnerabilityModified
CVE-2024-27095
The admin panel is subject to potential XSS attach in case the attacker manages to modify some records being uploaded to the server.
MEDIUM 4.8EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker manages to modify some records being uploaded to the server. This vulnerability is fixed in 0.27.6 and 0.28.1.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- decidim/decidim
- Source
- security-advisories@github.com
References
- https://github.com/decidim/decidim/releases/tag/v0.27.6Release Notes
- https://github.com/decidim/decidim/releases/tag/v0.28.1Release Notes
- https://github.com/decidim/decidim/security/advisories/GHSA-529p-jj47-w3m3Third Party Advisory
- https://github.com/decidim/decidim/releases/tag/v0.27.6Release Notes
- https://github.com/decidim/decidim/releases/tag/v0.28.1Release Notes
- https://github.com/decidim/decidim/security/advisories/GHSA-529p-jj47-w3m3Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.