6.1
CVSSv3

CVE-2017-12098

Published: 19/01/2018 Updated: 27/01/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

rails admin project rails admin 1.2.0

Vendor Advisories

Debian Bug report logs - #900178 ruby-rails-admin: CVE-2017-12098 Package: src:ruby-rails-admin; Maintainer for src:ruby-rails-admin is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 27 May 2018 06:51:05 UTC Severi ...