CVE-2020-8264
Description
In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the Actionable Exceptions middleware.
CWE
- CWE-79 — Cross-site Scripting (XSS) - Reflected (CWE-79)
Affected
- n/a / https://github.com/rails/rails — v=6.0.3.4 [affected]
CVSS
- (none)
References
- https://hackerone.com/reports/904059 x_refsource_MISC
- https://groups.google.com/g/rubyonrails-security/c/yQzUVfv42jk/m/oJWw-xhNAQAJ x_refsource_MISC
Source
cvelistV5-main/cves/2020/8xxx/CVE-2020-8264.json