CVE-2024-26143
Rails Possible XSS Vulnerability in Action Controller
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1.
Rails es un framework de aplicación web. Existe una posible vulnerabilidad XSS al utilizar los ayudantes de traducción en Action Controller. Las aplicaciones que utilizan métodos de traducción como traducir o t en un controlador, con una clave que termina en "_html", una clave :default que contiene entradas de usuario que no son de confianza y la cadena resultante se usa en una vista, pueden ser susceptibles a una vulnerabilidad XSS. La vulnerabilidad se solucionó en 7.1.3.1 y 7.0.8.1.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-02-14 CVE Reserved
- 2024-02-27 CVE Published
- 2024-06-11 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (6)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rails Search vendor "Rails" | Rails Search vendor "Rails" for product "Rails" | >= 7.0.0.0 < 7.0.8.1 Search vendor "Rails" for product "Rails" and version " >= 7.0.0.0 < 7.0.8.1" | en |
Affected
| ||||||
Rails Search vendor "Rails" | Rails Search vendor "Rails" for product "Rails" | >= 7.1.0.0 < 7.1.3.1 Search vendor "Rails" for product "Rails" and version " >= 7.1.0.0 < 7.1.3.1" | en |
Affected
|