CVE-2023-32693: Decidim Cross-site Scripting vulnerability in the external link redirections
Impact
The external link feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing.
Patches
The problem was patched in v0.27.3 and v0.26.7
Other sources
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The external link feature is susceptible to cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing. The problem was patched in versions 0.27.3 and 0.26.7.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-32693.
What is the impact of this vulnerability?
The impact of this vulnerability is that the external link feature is susceptible to cross-site scripting, allowing a remote attacker to execute JavaScript code.
What software is affected by this vulnerability?
The software affected by this vulnerability is Decidim Decidim version 0.25.0 to 0.26.6, Decidim Decidim version 0.26.7, and Decidim Decidim version 0.27.0 to 0.27.3.
How can I fix this vulnerability?
To fix this vulnerability, update to Decidim Decidim version 0.26.7 or 0.27.3.
What is the severity of this vulnerability?
The severity of this vulnerability is high with a CVSS score of 6.1.