Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node.
2016-02-16T02:59:03.970
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rubyonrails | html_sanitizer | ≤ 1.0.2 | Yes |
Application | rubyonrails | rails | 4.2.0 | No |
Application | rubyonrails | rails | 4.2.0 | No |
Application | rubyonrails | rails | 4.2.0 | No |
Application | rubyonrails | rails | 4.2.0 | No |
Application | rubyonrails | rails | 4.2.0 | No |
Application | rubyonrails | rails | 4.2.0 | No |
Application | rubyonrails | rails | 4.2.0 | No |
Application | rubyonrails | rails | 4.2.0 | No |
Application | rubyonrails | rails | 4.2.1 | No |
Application | rubyonrails | rails | 4.2.1 | No |
Application | rubyonrails | rails | 4.2.1 | No |
Application | rubyonrails | rails | 4.2.1 | No |
Application | rubyonrails | rails | 4.2.1 | No |
Application | rubyonrails | rails | 4.2.2 | No |
Application | rubyonrails | rails | 4.2.3 | No |
Application | rubyonrails | rails | 4.2.3 | No |
Application | rubyonrails | rails | 4.2.4 | No |
Application | rubyonrails | rails | 4.2.4 | No |
Application | rubyonrails | rails | 4.2.5 | No |
Application | rubyonrails | rails | 4.2.5 | No |
Application | rubyonrails | rails | 4.2.5 | No |
Application | rubyonrails | rails | 4.2.5.1 | No |
Application | rubyonrails | rails | 4.2.5.2 | No |
Application | rubyonrails | rails | 4.2.6 | No |
Application | rubyonrails | rails | 5.0.0 | No |
Application | rubyonrails | rails | 5.0.0 | No |
Application | rubyonrails | rails | 5.0.0 | No |
Application | rubyonrails | rails | 5.0.0 | No |