Decidim Cross-site Scripting vulnerability in the external link redirections
CVE-2023-32693
What is CVE-2023-32693?
The Decidim framework features a vulnerability related to its external link functionality, which is open to cross-site scripting attacks. This flaw allows attackers to execute malicious JavaScript code in the context of a user that is currently logged in. With this capability, an attacker could manipulate other users into unintentionally endorsing or supporting proposals. The vulnerability has been addressed in the recent updates, specifically in versions 0.27.3 and 0.26.7.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
decidim >= 0.25.0, < 0.26.7 < 0.25.0, 0.26.7
decidim >= 0.27.0, < 0.27.3 < 0.27.0, 0.27.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
