PT-2022-27174 · Unknown · Resque Scheduler
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Resque Scheduler version 1.27.4
Description
A remote attacker could inject javascript code to the
schedule job or args parameters in "/resque/delayed/jobs/{schedule job}?args={args id}" to execute javascript at the client side, resulting in a Cross-site scripting (XSS) issue.Recommendations
For Resque Scheduler version 1.27.4, update to version 4.10.2 to resolve the issue.
As a temporary workaround, consider avoiding clicks on 3rd party or untrusted links to the resque-web interface until the application is patched.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Resque Scheduler