Stored XSS Vulnerability in Active Admin for Ruby on Rails
CVE-2024-37031

6.1MEDIUM

Key Information:

Vendor
CVE Published:
3 June 2024

What is CVE-2024-37031?

The Active Admin framework for Ruby on Rails is susceptible to a stored cross-site scripting (XSS) vulnerability in versions prior to 3.2.2. This vulnerability arises in scenarios where users can create entities with arbitrary names, which are then edited in forms, leading to potential unauthorized script execution. This flaw, known as a 'dynamic form legends' issue, exposes applications utilizing Active Admin to an increased risk of exploitation, as attackers can craft and inject malicious scripts that may compromise user data and application integrity.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.