GHSA-j4h6-gcj7-7v9vMediumCVSS 7.7

decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embeds

Published
November 13, 2024
Last Modified
July 18, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL.

Patches

Not available

Workarounds

Disable the creation of meetings by participants in the meeting component.

References

OWASP ASVS v4.0.3-5.1.3

Credits

This issue was discovered in a security audit organized by mitgestalten Partizipationsbüro against Decidim. The security audit was implemented by the Austrian Institute of Technology.

🎯 Affected products1

  • rubygems/decidim-meetings:>= 0.28.0, < 0.28.3

🔗 References (4)