Логотип exploitDog
bind:CVE-2019-13146
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-13146

Количество 2

Количество 2

nvd логотип

CVE-2019-13146

больше 6 лет назад

The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-wg9m-gw3h-hg83

больше 6 лет назад

field_test gem contains injection vulnerability

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-13146

The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS).

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
github логотип
GHSA-wg9m-gw3h-hg83

field_test gem contains injection vulnerability

CVSS3: 5.3
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу