VDB

DEBIAN-CVE-2015-7578

DEBIAN-CVE-2015-7578 PUBLISHED CVSS 6.099999904632568 MEDIUM

Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes.

Risk Scores

CVSS v3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
Debian:11ruby-rails-html-sanitizer0, 0, 0
Debian:12ruby-rails-html-sanitizer0, 0, 0
Debian:13ruby-rails-html-sanitizer0, 0, 0
Debian:14ruby-rails-html-sanitizer0, 0, 0

Exploit Intelligence

Timeline

  • Feb 16, 2016 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›