CVE-2023-36465

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys. This issue has been patched in version 0.26.8 and 0.27.4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:decidim:decidim:*:*:*:*:*:ruby:*:*
cpe:2.3:a:decidim:decidim:*:*:*:*:*:ruby:*:*

History

21 Nov 2024, 08:09

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-06 12:15

Updated : 2024-11-21 08:09


NVD link : CVE-2023-36465

Mitre link : CVE-2023-36465

CVE.ORG link : CVE-2023-36465


JSON object : View

Products Affected

decidim

  • decidim
CWE
CWE-284

Improper Access Control

CWE-732

Incorrect Permission Assignment for Critical Resource