DOM-based Cross-Site Scripting in Rails Framework Affecting Rails-ujs
CVE-2023-23913

Currently unrated

Key Information:

Vendor

Rails

Status
Vendor
CVE Published:
9 January 2025

What is CVE-2023-23913?

A vulnerability exists in the Rails-ujs library, which can lead to DOM-based cross-site scripting (XSS) when utilizing HTML elements with the contenteditable attribute. This issue arises while pasting malicious HTML content from the clipboard that contains attributes such as data-method, data-remote, or data-disable-with. Attackers could potentially manipulate the clipboard input, resulting in unintended script execution within the targeted web application.

Affected Version(s)

rails-ujs 6.1.7.3

rails-ujs 7.0.4.3

rails-ujs 5.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.