Decidim: HTML content blocks allow stored script execution
A privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an HTML block, and the public page renders it with html_safe and no output escaping.
This issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an HTML block. The block is then rendered back through Decidim::ContentBlocks::HtmlCell#html_content without a sanitization boundary, so the script executes later in visitor's browsers.
See https://github.com/decidim/decidim/pull/16451
Do not give admin permissions to non-trustful users.
Stored XSS
This issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI.
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度 | 48.00 |
| 利用信号(无额外利用信号) | ×1.00 |
| VPI | 48.00 |
VPI 公式 vpi-v1