Decidim allows cross-site scripting (XSS) in the online or hybrid meeting embeds
Details
Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.28.3 and 0.29.0.