Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All users running an affected release should either upgrade or use one of the workarounds immediately.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
rails-html-sanitizer gem for Ruby 跨站脚本漏洞
Vulnerability Description
rails-html-sanitizer gem for Ruby是一款仅使用在Rails中的HTML清理程序。 rails-html-sanitizer gem for Ruby 1.0.4之前版本中存在跨站脚本漏洞,该漏洞源于程序没有正确的校验用户提交的输入。远程攻击者可利用该漏洞向Web页面中注入恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A