Decidim Vulnerable to XSS Attack in Version Control Feature
CVE-2024-41673
What is CVE-2024-41673?
A security vulnerability has been identified in the Decidim participatory democracy framework, specifically affecting its version control feature. The flaw exposes the framework to cross-site scripting (XSS) attacks through the manipulation of improperly formatted URLs. Attackers could exploit this weakness to execute arbitrary scripts in users' browsers when they interact with affected resources. To mitigate this issue, it is essential to update to version 0.27.8 or later, which includes security patches addressing this vulnerability. For further information, refer to the security advisory and commit linked below.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
decidim < 0.27.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
