Cross-Site Scripting Vulnerability in RailsAdmin by Sferik
CVE-2020-36190

6.1MEDIUM

Key Information:

Vendor
CVE Published:
12 January 2021

What is CVE-2020-36190?

RailsAdmin, a popular Ruby on Rails engine for managing data in web applications, is susceptible to a Cross-Site Scripting (XSS) vulnerability that arises when using nested forms. This flaw can allow attackers to inject malicious scripts through user inputs that are rendered in a web context, potentially compromising user sessions or leading to other security issues. This risk is present in all versions before 1.4.3 and 2.x versions prior to 2.0.2. It is essential for users to upgrade to the latest versions to mitigate this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.