PT-2018-5349 · Ruby On Rails · Rails Admin

CVE-2017-12098

·

Publicado

2018-01-19

·

Atualizado

2023-01-27

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions rails admin rails gem version 1.2.0
Description A cross site scripting (XSS) issue exists in the add filter functionality. This can be triggered by a specially crafted URL, allowing an attacker to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this issue.
Recommendations For rails admin rails gem version 1.2.0, consider disabling the add filter functionality until a patch is available to prevent exploitation. Restrict access to the add filter feature to minimize the risk of arbitrary javascript execution. Avoid using the add filter functionality in the rails admin rails gem until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-12098
GHSA-PXR8-W3JQ-RCWJ

Produtos afetados

Rails Admin