Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-23913

Опубликовано: 09 янв. 2025
Источник: debian
EPSS Низкий

Описание

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2:6.1.7.3+dfsg-1package

Примечания

  • https://github.com/rails/rails/commit/5037a13614d71727af8a175063bcf6ba1a74bdbd (v6.1.7.3)

  • https://discuss.rubyonrails.org/t/cve-2023-23913-dom-based-cross-site-scripting-in-rails-ujs-for-contenteditable-html-elements/82468

EPSS

Процентиль: 47%
0.00643
Низкий

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 1 года назад

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

CVSS3: 7.5
redhat
больше 3 лет назад

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

CVSS3: 6.3
nvd
больше 1 года назад

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

suse-cvrf
почти 3 года назад

Security update for rubygem-actionview-5_1

CVSS3: 6.3
github
около 3 лет назад

rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements

EPSS

Процентиль: 47%
0.00643
Низкий