6.5 Medium
AI Score
Confidence
Low
0.003 Low
EPSS
Percentile
70.3%
Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.
secunia.com/advisories/41930
securitytracker.com/id?1024624
weblog.rubyonrails.org/2010/10/15/security-vulnerability-in-nested-attributes-code-in-ruby-on-rails-2-3-9-and-3-0-0
www.vupen.com/english/advisories/2010/2719