logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-26143

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-26143

Description:
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1.
Last updated date:
02/13/2025
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/13/2025
Reference url to background

https://discuss.rubyonrails.org/t/possible-xss-vulnerability-in-action-controller/84947

Type:
exploit
Confidence:
HIGH
Date of publishing:
02/13/2025
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/13/2025
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy