#VU93641 Cross-site scripting in Ruby on Rails - CVE-2024-32464
Published: July 2, 2024
Ruby on Rails
Rails
Description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in ActionText::Attachable::ContentAttachment when parsing attachments. A remote attacker can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.