Decidim Pagination Feature Vulnerable to XSS Attack
CVE-2024-32469
7.1HIGH
What is CVE-2024-32469?
The Decidim framework, designed for participatory democracy, has a vulnerability related to its pagination feature utilized in searches and filters. This vulnerability allows for a potential Cross-Site Scripting (XSS) attack when an attacker submits a malformed URL using the GET parameter 'per_page'. To mitigate this risk, it is essential for users to update to at least versions 0.27.6 or 0.28.1, where the issue has been addressed.
Affected Version(s)
decidim < 0.27.6 < 0.27.6
decidim >= 0.28.0.rc1, < 0.28.1 < 0.28.0.rc1, 0.28.1