CVE-2012-3465

Description

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.333

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2012-2660,CVE-2012-3465 are fixed in Ruby-actionpack 2.3.16Windows
Vulnerabilities CVE-2012-3463,CVE-2012-3465 are fixed in Ruby-actionpack 3.1.8Windows
Vulnerabilities CVE-2012-3463,CVE-2012-3465 are fixed in Ruby-actionpack 3.2.8Windows
Vulnerabilities CVE-2012-3463,CVE-2012-3465 are fixed in Ruby-actionpack 3.0.17Windows
Vulnerabilities CVE-2012-2660,CVE-2012-3465 are fixed in Ruby-actionpack for Linux 2.3.16Linux
Vulnerabilities CVE-2012-3463,CVE-2012-3465 are fixed in Ruby-actionpack for Linux 3.1.8Linux
Vulnerabilities CVE-2012-3463,CVE-2012-3465 are fixed in Ruby-actionpack for Linux 3.2.8Linux
Vulnerabilities CVE-2012-3463,CVE-2012-3465 are fixed in Ruby-actionpack for Linux 3.0.17Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234