decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embeds
The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL.
The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL.
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. Decidim uses a third-party library named Ransack for filtering certain database collections (e.g., public meetings). By default, this library allows filtering on all data attributes and associations. This allows an unauthenticated remote attacker to exfiltrate non-public data from the underlying database of a Decidim instance (e.g., exfiltrating …