XSS Vulnerability in Decidim's QuillJS Editor
CVE-2024-39910
What is CVE-2024-39910?
The Decidim platform, which facilitates citizen participation in governance, has a Cross-Site Scripting (XSS) vulnerability tied to its WYSIWYG editor, QuillJS. An attacker could exploit this flaw by crafting malicious HTML that could be executed on the server during upload, potentially leading to unauthorized script execution. Users are strongly recommended to upgrade to version 0.27.7 to mitigate risks. For those unable to upgrade immediately, it is crucial to reassess user permissions for accounts with access to the admin panel and consider disabling the rich text editor feature for participants.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
