CVE-2013-4491: XSS
Cross-site scripting (XSS) vulnerability in actionpack/lib/actionview/helpers/translationhelper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
Other sources
Cross-site scripting (XSS) vulnerability in actionpack/lib/actionview/helpers/translationhelper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4491?
CVE-2013-4491 is classified as a medium severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2013-4491?
To mitigate CVE-2013-4491, upgrade your Ruby on Rails to version 3.2.16 or 4.0.2 or later.
What types of attacks can be executed against CVE-2013-4491?
CVE-2013-4491 allows attackers to execute cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
Which versions of Ruby on Rails are affected by CVE-2013-4491?
CVE-2013-4491 affects Ruby on Rails versions prior to 3.2.16 and 4.0.2.
Is CVE-2013-4491 a common vulnerability?
CVE-2013-4491 is a known vulnerability affecting many applications built on older versions of Ruby on Rails.