CVE-2024-45594
HIGHDecidim 0.28.0-0.28.2 - Cross-Site Scripting via Meeting Embed URL
Title source: llmDescription
Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.28.3 and 0.29.0.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_confirm
https://github.com/decidim/decidim/security/advisories/GHSA-j4h6-gcj7-7v9v
Scores
CVSS v3
7.7
EPSS
0.0029
EPSS Percentile
52.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (2)
decidim/decidim
0.28.0 - 0.28.3
rubygems/decidim-meetings
0.28.0 - 0.28.3RubyGems
Published
Nov 13, 2024
Tracked Since
Feb 18, 2026