Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2023-23913

больше 1 года назад

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2023-23913

больше 3 лет назад

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-23913

больше 1 года назад

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2023-23913

больше 1 года назад

There is a potential DOM based cross-site scripting issue in rails-ujs ...

CVSS3: 6.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3813-1

почти 3 года назад

Security update for rubygem-actionview-5_1

EPSS: Низкий
github логотип

GHSA-xp5h-f8jf-rc8q

около 3 лет назад

rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-23913

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-23913

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-23913

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
debian логотип
CVE-2023-23913

There is a potential DOM based cross-site scripting issue in rails-ujs ...

CVSS3: 6.3
1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:3813-1

Security update for rubygem-actionview-5_1

1%
Низкий
почти 3 года назад
github логотип
GHSA-xp5h-f8jf-rc8q

rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements

CVSS3: 6.3
1%
Низкий
около 3 лет назад

Уязвимостей на страницу