CVE-2023-47635: Possible CSRF attack at questionnaire templates preview
4.5
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.23821%
CWE
Published
2/20/2024
Updated
2/20/2024
KEV Status
No
Technology
Ruby
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| decidim-templates | rubygems | >= 0.23.0, < 0.27.5 | 0.27.5 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stems from the 'skip_before_action' directive disabling CSRF protection for the preview endpoint. The commit diff shows this line was added in the vulnerable version and removed in the patch. The CWE-352 (CSRF) mapping and advisory details confirm this configuration error directly enables CSRF attacks on the preview functionality.