Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12098

Опубликовано: 19 янв. 2018
Источник: debian
EPSS Низкий

Описание

An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-rails-adminremovedpackage
ruby-rails-adminno-dsastretchpackage

Примечания

  • https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0450

  • https://github.com/sferik/rails_admin/issues/2985

  • https://github.com/sferik/rails_admin/commit/44f09ed72b5e0e917a5d61bd89c48d97c494b41c

EPSS

Процентиль: 60%
0.00397
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 8 лет назад

An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability.

CVSS3: 6.1
nvd
около 8 лет назад

An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability.

CVSS3: 6.1
github
почти 8 лет назад

rails_admin ruby gem XSS

EPSS

Процентиль: 60%
0.00397
Низкий