Back

MEDIUM

rubygem-actionpack: XSS in the 'translate' helper method

Published Nov 28, 2011

Description

Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an "html" substring.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 28, 2011
Updated Aug 7, 2024
Reserved Nov 4, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Nov 18, 2011
GHSA-XXR8-833V-C7WC