CVE-2013-0256

EPSS 2.7%

RDoc contains XSS vulnerability

Published: 10/24/2017Modified: 12/8/2024
Also known as:GHSA-v2r9-c84j-v7xm

Description

darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.

Affected packages (1)

References (14)