Decidim是Decidim组织开源的一个参与式民主框架,用 Ruby on Rails 编写。 Decidim 0.30.9之前版本、0.31.0至0.31.5之前版本和0.32.0.rc1至0.32.0.rc2之前版本存在SQL注入漏洞,该漏洞源于对GET /admin/organization/users搜索中参数term未进行清理,直接插入到Arel.sql的ORDER BY similarity表达式,可能导致经过身份验证的组织管理员执行盲PostgreSQL表达式并通过时间差异推断数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45377 | 6.5 MEDIUM | Decidim: Private exports can be downloaded through reusable links |
| CVE-2026-45086 | 5.4 MEDIUM | Decidim: Forms admin question editor lacks authorization |
| CVE-2026-45330 | 4.9 MEDIUM | Decidim: Verification admins can access supplied IDs from other organisations |
No comments yet