RubySec

Providing security resources for the Ruby community

CVE-2023-25309 (rollout-ui): Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui gem v0.5

Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui gem v0.5

Published: May 23, 2023

SECURITY IDENTIFIERS

GEM

rollout-ui

SEVERITY

CVSS v3.x: 6.1 (Medium)

PATCHED VERSIONS

>= 0.5.3

DESCRIPTION

Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality.

RELATED