Vulnerability CVE-2024-41673


Published: 2024-10-01

Description:
Decidim is a participatory democracy framework. The version control feature used in resources is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.27.8.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://github.com/decidim/decidim/security/advisories/GHSA-cc4g-m3g7-xmw8
https://github.com/decidim/decidim/commit/8a18c8b1ee85a1b35ee0d8d5893f218695d15637

Copyright 2026, cxsecurity.com

 

Back to Top