6
CVE-2026-45415
- EPSS 0.4%
- Veröffentlicht 06.08.2026 22:17:07
- Zuletzt bearbeitet 07.08.2026 16:17:24
- CVE-Watchlists
- Unerledigt
Decidim: CSV census record endpoints improper authorization
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorization before rendering or mutating Decidim::Verifications::CsvDatum, allowing a participant manager to create, alter, or remove census records. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerdecidim
≫
Produkt
decidim
Version
< 0.30.9
Status
affected
Version
>= 0.31.0.rc1, < 0.31.5
Status
affected
Version
>= 0.32.0.rc1, < 0.32.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.325 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6 | 1.2 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/decidim/decidim/pull/16674
https://github.com/decidim/decidim/pull/16703
https://github.com/decidim/decidim/security/advisories/GHSA-q79h-67vx-m9xg