{"id":"CVE-2024-43415","aliases":["GHSA-cxwf-qc32-375f"],"url":"https://o3.security/vulnerability/CVE-2024-43415","summary":"Decidim-Awesome: SQL injection in AdminAccountability","details":"## Vulnerability type: \nCWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\n## Vendor: \nDecidim International Community Environment\n\n### Has vendor conﬁrmed: \nYes\n\n### Attack type:\nRemote\n\n### Impact:\nCode Execution\nEscalation of Privileges\nInformation Disclosure\n\n### Aﬀected component:\nA raw sql-statement that uses an interpolated variable exists in the admin_role_actions method of the\n`papertrail/version-model(app/models/decidim/decidim_awesome/paper_trail_version.rb`).\n\n### Attack vector:\n\nAn attacker with admin permissions could manipulate database queries in order to read out the database,\nread ﬁles from the ﬁlesystem, write ﬁles from the ﬁlesystem. In the worst case, this could lead to remote code\nexecution on the server.\nDescription of the vulnerability for use in the CVE [ℹ] (https://cveproject.github.io/docs/content/key-details-\nphrasing.pdf) : An improper neutralization of special elements used in an SQL command in the `papertrail/version-\nmodel` of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries\nto disclose information, read and write files or execute commands.\n\n### Discoverer Credits:\nWolfgang Hotwagner\n\n### References:\nhttps://pentest.ait.ac.at/security-advisory/decidim-awesome-sql-injection-in-adminaccountability/\nhttps://portswigger.net/web-security/sql-injection","published":"2024-11-12T15:45:51.312Z","modified":"2026-08-12T03:51:09.694721540Z","cvss":{"score":9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"decidim-decidim_awesome","fixedVersion":"0.10.3"},{"ecosystem":"RubyGems","name":"decidim-decidim_awesome","fixedVersion":"0.11.2"}],"fix":{"url":"https://github.com/decidim-ice/decidim-module-decidim_awesome/commit/84374037d34a3ac80dc18406834169c65869f11b","label":"decidim-ice/decidim-module-decidim_awesome@8437403"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/43xxx/CVE-2024-43415.json"},{"type":"ADVISORY","url":"https://github.com/decidim-ice/decidim-module-decidim_awesome/security/advisories/GHSA-cxwf-qc32-375f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-43415"},{"type":"ADVISORY","url":"https://pentest.ait.ac.at/security-advisory/decidim-awesome-sql-injection-in-adminaccountability"},{"type":"FIX","url":"https://github.com/decidim-ice/decidim-module-decidim_awesome/commit/84374037d34a3ac80dc18406834169c65869f11b"},{"type":"PACKAGE","url":"https://github.com/decidim-ice/decidim-module-decidim_awesome"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/decidim-decidim_awesome/CVE-2024-43415.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:09.694721540Z"}}