XSS Vulnerability in Decidim's QuillJS Editor
CVE-2024-39910
4.8MEDIUM
What is CVE-2024-39910?
The Decidim platform, which facilitates citizen participation in governance, has a Cross-Site Scripting (XSS) vulnerability tied to its WYSIWYG editor, QuillJS. An attacker could exploit this flaw by crafting malicious HTML that could be executed on the server during upload, potentially leading to unauthorized script execution. Users are strongly recommended to upgrade to version 0.27.7 to mitigate risks. For those unable to upgrade immediately, it is crucial to reassess user permissions for accounts with access to the admin panel and consider disabling the rich text editor feature for participants.