Cross-Site Scripting Vulnerability in RailsAdmin by Sferik
CVE-2020-36190
6.1MEDIUM
What is CVE-2020-36190?
RailsAdmin, a popular Ruby on Rails engine for managing data in web applications, is susceptible to a Cross-Site Scripting (XSS) vulnerability that arises when using nested forms. This flaw can allow attackers to inject malicious scripts through user inputs that are rendered in a web context, potentially compromising user sessions or leading to other security issues. This risk is present in all versions before 1.4.3 and 2.x versions prior to 2.0.2. It is essential for users to upgrade to the latest versions to mitigate this vulnerability.
