decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embeds
Description
Published by the National Vulnerability Database
Nov 13, 2024
Published to the GitHub Advisory Database
Nov 13, 2024
Reviewed
Nov 13, 2024
Last updated
Nov 13, 2024
Impact
The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL.
Patches
Not available
Workarounds
Disable the creation of meetings by participants in the meeting component.
References
OWASP ASVS v4.0.3-5.1.3
Credits
This issue was discovered in a security audit organized by mitgestalten Partizipationsbüro against Decidim. The security audit was implemented by the Austrian Institute of Technology.
References