Back

MEDIUM

ruby-activesupport: XSS vulnerability

Published Sep 8, 2009

Description

Cross-site scripting (XSS) vulnerability in Ruby on Rails 2.x before 2.2.3, and 2.3.x before 2.3.4, allows remote attackers to inject arbitrary web script or HTML by placing malformed Unicode strings into a form helper.

Affected products

Remediation

No remediation recorded yet.

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 8, 2009
Updated Aug 7, 2024
Reserved Aug 29, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Sep 3, 2009
GHSA-8QRH-H9M2-5FVF