Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12150
HistoryJan 15, 2019 - 9:13 a.m.

Cross-Site Scripting (XSS)

2019-01-1509:13:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.003 Low

EPSS

Percentile

69.9%

The actionview module in ruby on rails is vulnerable to Cross-Site Scripting (XSS) attacks. This is due to a lack of escaping double quotes, allowing malicious users to execute arbitrary code.