Cross-site scripting - CVE-2013-4492
Published: December 7, 2013 / Updated: August 3, 2020
Detailed vulnerability description
Vulnerability allows a remote attacker to perform Cross-site scripting attacks.
An input validation error exists in exceptions.rb in the i18n gem before 0.6.6 for Ruby. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
How to mitigate CVE-2013-4492
Sources
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00093.html
- http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/
- http://www.debian.org/security/2013/dsa-2830
- http://www.securityfocus.com/bid/64076
- https://github.com/svenfuchs/i18n/commit/92b57b1e4f84adcdcc3a375278f299274be62445
- https://groups.google.com/forum/message/raw?msg=ruby-security-ann/pLrh6DUw998/bLFEyIO4k_EJ