Decidim是Decidim组织开源的一个参与式民主框架,用 Ruby on Rails 编写。 Decidim 0.31.1至0.31.5之前版本和0.32.0.rc1至0.32.0.rc2之前版本存在授权问题漏洞,该漏洞源于对/admin/demographics/questions路由的访问控制不当,未验证调用者是否为管理员,导致普通参与者可访问受保护的管理编辑器界面。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45377 | 6.5 MEDIUM | Decidim: Private exports can be downloaded through reusable links |
| CVE-2026-45376 | 5.5 MEDIUM | Decidim: Admin user search allows SQL injection through similarity-based sorting |
| CVE-2026-45330 | 4.9 MEDIUM | Decidim: Verification admins can access supplied IDs from other organisations |
No comments yet