CVE-2013-6416

EPSS 0.24%

actionpack Cross-site Scripting vulnerability

Published: 10/24/2017Modified: 12/3/2024
Also known as:GHSA-w37c-q653-qg95

Description

Cross-site scripting (XSS) vulnerability in the simple_format helper in `actionpack/lib/action_view/helpers/text_helper.rb` in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

Affected packages (1)

References (8)