Sploitus

CVE-2023-47635

No indexed exploits for CVE-2023-47635 yet

Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check is disabled for the questionnaire templates preview. The issue does not imply a serious security thread as you need to have access also to the session cookie in order to see this resource. This URL does not allow modifying the resource but it may allow attackers to gain access to information which was not meant to be public. The issue is fixed in version 0.27.5 and 0.28.0. As a workaround, disable the templates functionality or remove all available templates.

Affected products
Decidim
Decidim
< 0.27.5
Fix
Available
CVSS 3.1
5.7 MEDIUM
EPSS
0.3% (24th percentile)
Weakness
CWE-918, CWE-352
NVD status
Analyzed
Published
2024-02-20
CVE-2023-47635 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-47635 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-47635 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.