RubySec

Providing security resources for the Ruby community

OSVDB-125713 (spree): Potential XSS vulnerability related to the analytics dashboard

Potential XSS vulnerability related to the analytics dashboard

Published: July 02, 2012

SECURITY IDENTIFIERS

GEM

spree

PATCHED VERSIONS

~> 0.11.4 ~> 0.70.6 ~> 1.0.5 >= 1.1.2

DESCRIPTION

Spree has a flaw in its analytics dashboard where keywords are not escaped, leading to potential XSS.

RELATED