Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yasins

#47232of 53,632
5.4Total CVSS
Vulnerabilities · 1
PT-2018-2643
5.4
2018-10-30
Ruby · Loofah · CVE-2018-16468
**Name of the Vulnerable Software and Affected Versions** Loofah gem for Ruby versions through 2.2.2 **Description** The issue is related to insufficient sanitization of SVG elements in JavaScript, which can lead to the occurrence of unsanitized JavaScript in sanitized output when a crafted SVG element is republished. This can allow a remote attacker to inject arbitrary JavaScript code. **Recommendations** For versions through 2.2.2, upgrade to version 2.2.3 to resolve the issue.