脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Cross-site scripting (XSS) in the decidim admin activity log
脆弱性説明
decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The admin panel is subject to potential Cross-site scripting (XSS) attach in case an admin assigns a valuator to a proposal, or does any other action that generates an admin activity log where one of the resources has an XSS crafted. This issue has been addressed in release version 0.27.7, 0.28.2, and newer. Users are advised to upgrade. Users unable to upgrade may redirect the pages /admin and /admin/logs to other admin pages to prevent this access (i.e. `/admin/organization/edit`).
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
脆弱性タイプ
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
脆弱性タイトル
Decidim 跨站脚本漏洞
脆弱性説明
Decidim是Decidim开源的一个参与式民主框架,用 Ruby on Rails 编写。 Decidim 0.27.6及之前版本和0.28.1及之前版本存在跨站脚本漏洞,该漏洞源于在管理员面板中,若管理员为某个提案分配评估者或执行任何会产生管理活动日志的操作,则可能导致跨站脚本攻击。
CVSS情報
N/A
脆弱性タイプ
N/A