PT-2026-89201 · Rubygems · Decidim-Elections
CVE-2026-44282
·
Publicado
2026-09-09
·
Atualizado
2026-09-09
CVSS v3.1
4.8
Média
| Vetor | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Description
A low-privilege process-scoped admin who can manage elections can store arbitrary HTML in the question statement/body without sanitization, and the public elections UI renders that value unsafely.
Technical description
This stored XSS appears because election question titles are rendered as trusted HTML instead of sanitized text. The election question editor stores
question.body as a normal translatable string, and the public helper question title returns that value with html safe and no sanitization boundary, so any user who can edit election questions can persist markup or script-bearing payloads that later render on public election pages.Impact
A low-privilege process-scoped admin or other election editor with question-management rights can persist JavaScript that executes in visitor's browsers on public election pages and voting booth screens.
Patches
Workarounds
Developers should review their implementation's administrator accesses and not give access to untrustworthy users
Resources
OWASP XSS Injection
Credits
This issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Decidim-Elections