VDB

DEBIAN-CVE-2016-6316

DEBIAN-CVE-2016-6316 PUBLISHED CVSS 6.099999904632568 MEDIUM

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.

Risk Scores

CVSS v3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
Debian:13rails0, 0, 0
Debian:14rails0, 0, 0
Debian:11rails0, 0, 0
Debian:12rails0, 0, 0

Timeline

  • Sep 7, 2016 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›