CVE-2023-36465 – decidim
Package
Manager: gem
Name: decidim
Vulnerable Version: >=0.23.2 <0.26.8 || >=0.27.0 <0.27.4
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
EPSS: 0.0007 pctl0.21829
Details
Decidim has broken access control in templates ### Impact The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys.
Metadata
Created: 2023-10-05T20:52:46Z
Modified: 2023-10-13T22:47:57Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-639h-86hw-qcjq/GHSA-639h-86hw-qcjq.json
CWE IDs: ["CWE-284", "CWE-732"]
Alternative ID: GHSA-639h-86hw-qcjq
Finding: F039
Auto approve: 1