DOM-based Cross-Site Scripting in Rails Framework Affecting Rails-ujs
CVE-2023-23913
Currently unrated
What is CVE-2023-23913?
A vulnerability exists in the Rails-ujs library, which can lead to DOM-based cross-site scripting (XSS) when utilizing HTML elements with the contenteditable attribute. This issue arises while pasting malicious HTML content from the clipboard that contains attributes such as data-method, data-remote, or data-disable-with. Attackers could potentially manipulate the clipboard input, resulting in unintended script execution within the targeted web application.
Affected Version(s)
rails-ujs 6.1.7.3
rails-ujs 7.0.4.3
rails-ujs 5.1.0