Skip to content

Oxidized Web vulnerable to Cross-site Scripting

Moderate severity GitHub Reviewed Published Dec 27, 2022 to the GitHub Advisory Database • Updated Mar 1, 2024

Package

bundler oxidized-web (RubyGems)

Affected versions

<= 0.13.1

Patched versions

None

Description

A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The manipulation of the argument to_research leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45. It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier assigned to this vulnerability.

References

Published by the National Vulnerability Database Dec 27, 2022
Published to the GitHub Advisory Database Dec 27, 2022
Reviewed Jan 9, 2023
Last updated Mar 1, 2024

Severity

Moderate
5.4
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CVE ID

CVE-2019-25088

GHSA ID

GHSA-8qwh-rm6c-jv96

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.