Lucene search

K
prionPRIOn knowledge basePRION:CVE-2010-3933
HistoryOct 28, 2010 - 12:00 a.m.

Design/Logic Flaw

2010-10-2800:00:00
PRIOn knowledge base
www.prio-n.com
8

7.1 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.3%

Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.

CPENameOperatorVersion
railseq2.3.9
railseq3.0.0

7.1 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.3%