Decidim

Decidim

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.58%
  • Veröffentlicht 20.02.2024 18:15:50
  • Zuletzt bearbeitet 16.12.2024 21:46:47

Decidim is a participatory democracy framework. Starting in version 0.4.rc3 and prior to version 2.0.9 of the `devise_invitable` gem, the invites feature allows users to accept the invitation for an unlimited amount of time through the password reset...

  • EPSS 0.49%
  • Veröffentlicht 20.02.2024 18:15:50
  • Zuletzt bearbeitet 16.12.2024 22:43:27

Decidim is a participatory democracy framework. Starting in version 0.27.0 and prior to versions 0.27.5 and 0.28.0, the dynamic file upload feature is subject to potential cross-site scripting attacks in case the attacker manages to modify the file n...

  • EPSS 0.07%
  • Veröffentlicht 06.10.2023 12:15:11
  • Zuletzt bearbeitet 21.11.2024 08:09:46

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any lo...

  • EPSS 0.12%
  • Veröffentlicht 11.07.2023 18:15:16
  • Zuletzt bearbeitet 21.11.2024 08:06:31

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The processes filter feature is susceptible to Cross-site scripting. This allow...

  • EPSS 0.26%
  • Veröffentlicht 11.07.2023 18:15:16
  • Zuletzt bearbeitet 21.11.2024 08:06:31

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. Decidim uses a third-party library named Ransack for filtering certain database...

  • EPSS 0.18%
  • Veröffentlicht 11.07.2023 18:15:14
  • Zuletzt bearbeitet 21.11.2024 08:03:51

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The external link feature is susceptible to cross-site scripting. This allows a...