Rails是美国Rails团队的一套基于Ruby语言的开源Web应用框架。 Rails rails-html-sanitizer 1.0.3到1.4.4版本存在跨站脚本漏洞,该漏洞源于当与 Loofah 结合使用时, 容易受到通过数据 URI 的跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rails | rails-html-sanitizer | >= 1.0.3, < 1.4.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-23517 | 7.5 HIGH | Inefficient Regular Expression Complexity in rails-html-sanitizer |
| CVE-2022-23519 | 7.2 HIGH | Possible XSS vulnerability with certain configurations of rails-html-sanitizer |
| CVE-2022-23520 | 6.1 MEDIUM | rails-html-sanitizer contains an incomplete fix for an XSS vulnerability |
No comments yet