Cross-Site Scripting Vulnerability in Rails Admin Gem by Rails
CVE-2017-12098

6.1MEDIUM

Key Information:

Vendor
CVE Published:
19 January 2018

What is CVE-2017-12098?

A cross-site scripting (XSS) vulnerability exists in the add filter functionality of the Rails Admin gem in version 1.2.0. This security flaw can be exploited through specially crafted URLs, allowing attackers to execute arbitrary JavaScript in the browser of an authenticated user. By leveraging this XSS vulnerability, attackers can potentially perform phishing attacks, deceiving users into executing malicious scripts.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.