Lucene search

K
osvGoogleOSV:GHSA-PC3M-V286-2JWJ
HistoryOct 24, 2017 - 6:33 p.m.

actionview Cross-site Scripting vulnerability

2017-10-2418:33:35
Google
osv.dev
10

0.003 Low

EPSS

Percentile

69.9%

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as “HTML safe” and used as attribute values in tag handlers.