CVE-2023-36825

CVE-2023-36825

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. This vulnerability is related to the deserialization of untrusted data from the `_state` query parameter, which can result in remote code execution. The issue has been addressed in version `14.5.0`. Users are advised to upgrade their software to this version or any subsequent versions that include the patch.

Source: CVE-2023-36825

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다