Decidim: HTML content blocks allow stored script execution
A privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an HTML block, and the public page renders it with html_safe and no output escaping.
This issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an HTML block. The block is then rendered back through Decidim::ContentBlocks::HtmlCell#html_content without a sanitization boundary, so the script executes later in visitor's browsers.
See https://github.com/decidim/decidim/pull/16451
Do not give admin permissions to non-trustful users.
Stored XSS
This issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도 | 48.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 48.00 |
VPI 공식 vpi-v1 기준