CVE-2024-39910
Last modified
CVE-2024-39910 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The WYSWYG editor QuillJS is subject to potential XSS attach in case the attacker manages to modify the HTML before being uploaded to the server. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The WYSWYG editor QuillJS is subject to potential XSS attach in case the attacker manages to modify the HTML before being uploaded to the server. The attacker is able to change e.g. to <svg onload=alert('XSS')> if they know how to craft these requests themselves. This issue has been addressed in release version 0.27.7. All users are advised to upgrade. Users unable to upgrade should review the user accounts that have access to the admin panel (i.e. general Administrators, and participatory space's Administrators) and remove access to them if they don't need it. Disable the "Enable rich text editor for participants" setting in the admin dashboard
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Decidim | Decidim | < 0.27.7 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-39910?
How severe is CVE-2024-39910?
How do I fix CVE-2024-39910?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-39905Red is a fully modular Discord bot. Due to a bug in Red's Co…5.3
- CVE-2024-39906A command injection vulnerability was found in the IndieAuth…8.3
- CVE-2024-399071Panel is a web-based linux server management control panel.…9.8
- CVE-2024-39908 REXML is an XML toolkit for Ruby. The REXML gem before 3.3.…4.3
- CVE-2024-39909KubeClarity is a tool for detection and management of Softwa…6.5
- CVE-2024-3991The ShopLentor – WooCommerce Builder for Elementor & Gutenbe…5.4
- CVE-2024-399111Panel is a web-based linux server management control panel.…9.8
- CVE-2024-39912web-auth/webauthn-lib is an open source set of PHP libraries…5.3
- CVE-2024-39914FOG is a cloning/imaging/rescue suite/inventory management s…9.8
- CVE-2024-39915Thruk is a multibackend monitoring webinterface for Naemon, …9.9
- CVE-2024-39916FOG is a free open-source cloning/imaging/rescue suite/inven…6.4
- CVE-2024-39917xrdp is an open source RDP server. xrdp versions prior to 0.…9.8
Are you affected by CVE-2024-39910?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
