PT-2022-7468 · Ruby On Rails+2 · Action Pack+2

Freakyclown

·

Published

2022-10-26

·

Updated

2024-08-28

·

CVE-2022-3704

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions actionpack (affected versions not specified)
Description The issue is related to the incorrect neutralization of input data during web page generation, potentially leading to cross-site scripting. It affects the file actionpack/lib/action dispatch/middleware/templates/routes/ table.html.erb. The manipulation can be initiated remotely, but the existence of this vulnerability is still disputed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Improper Neutralization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06602
BIT-RAILS-2022-3704
CVE-2022-3704
GHSA-9CHR-4FJH-5RGW

Affected Products

Debian
Red Os
Action Pack