CVE-2024-45594: Decidim allows cross-site scripting (XSS) in the online or hybrid meeting embeds
Impact
The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL.
Patches
Not available
Workarounds
Disable the creation of meetings by participants in the meeting component.
References
OWASP ASVS v4.0.3-5.1.3
Credits
This issue was discovered in a security audit organized by mitgestalten Partizipationsbüro against Decidim. The security audit was implemented by the Austrian Institute of Technology.
Other sources
Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.28.3 and 0.29.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45594?
CVE-2024-45594 has a medium severity rating due to its potential to facilitate cross-site scripting (XSS) attacks.
How do I fix CVE-2024-45594?
Currently, there are no patches available for CVE-2024-45594.
What is the recommended workaround for CVE-2024-45594?
To mitigate CVE-2024-45594, disable the creation of meetings by participants in the meeting component.
Which software versions are affected by CVE-2024-45594?
CVE-2024-45594 affects versions of the decidim-meetings package between 0.28.0 and 0.28.3.
What type of attack is possible with CVE-2024-45594?
CVE-2024-45594 is subject to potential Cross-Site Scripting (XSS) attacks through a malformed URL.