Improper Access Control Affecting decidim-templates package, versions >=0.23.2, <0.26.8 >=0.27.0, <0.27.4
Threat Intelligence
EPSS
0.09% (41st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-DECIDIMTEMPLATES-5936340
- published 6 Oct 2023
- disclosed 5 Oct 2023
- credit Andrés Pereira de Lucena
Introduced: 5 Oct 2023
CVE-2023-36465 Open this link in a new tabHow to fix?
Upgrade decidim-templates
to version 0.26.8, 0.27.4 or higher.
Overview
decidim-templates is a This module provides a solution to create templates for different Decidim models, such as Proposals and Questionnaires.
Affected versions of this package are vulnerable to Improper Access Control due to the broken access control in the templates
module. An attacker can manipulate, create, or delete templates of surveys by accessing the administration panel.
Note:
This is only exploitable if the attacker is a logged-in user.
References
CVSS Scores
version 3.1