Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-23913

Опубликовано: 09 янв. 2025
Источник: nvd
CVSS3: 6.3
EPSS Низкий

Описание

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

EPSS

Процентиль: 15%
0.00048
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 1 года назад

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

CVSS3: 7.5
redhat
почти 3 года назад

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

CVSS3: 6.3
debian
около 1 года назад

There is a potential DOM based cross-site scripting issue in rails-ujs ...

suse-cvrf
больше 2 лет назад

Security update for rubygem-actionview-5_1

CVSS3: 6.3
github
больше 2 лет назад

rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements

EPSS

Процентиль: 15%
0.00048
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-79