You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Decidim cross-site scripting (XSS) in the pagination
Moderate severity
GitHub Reviewed
Published
Jul 10, 2024
in
decidim/decidim
•
Updated Nov 18, 2024
Impact
The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using the GET parameter
per_page
.Patches
Not available
Workarounds
Not available
References
OWASP ASVS v4.0.3-5.1.3
Credits
This issue was discovered in a security audit organized by the mitgestalten Partizipationsbüro and funded by netidee against Decidim done during April 2024. The security audit was implemented by AIT Austrian Institute of Technology GmbH,
References