CVE-2013-6415: XSS
Cross-site scripting (XSS) vulnerability in the numbertocurrency helper in actionpack/lib/actionview/helpers/numberhelper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
Other sources
Cross-site scripting (XSS) vulnerability in the numbertocurrency helper in actionpack/lib/actionview/helpers/numberhelper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/actionpackto a version that resolves this vulnerability.Fixed in 4.0.2 - Upgrade
Upgrade
rubygems/actionpackto a version that resolves this vulnerability.Fixed in 3.2.16
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6415?
CVE-2013-6415 is classified as a medium severity vulnerability due to its potential for remote code execution via XSS.
How do I fix CVE-2013-6415?
To fix CVE-2013-6415, upgrade to Ruby on Rails version 3.2.16 or 4.0.2 or later.
What are the affected versions for CVE-2013-6415?
CVE-2013-6415 affects Ruby on Rails versions prior to 3.2.16 and 4.x before 4.0.2.
What does CVE-2013-6415 exploit?
CVE-2013-6415 exploits a cross-site scripting vulnerability in the number_to_currency helper in Ruby on Rails.
Can CVE-2013-6415 be detected?
Yes, CVE-2013-6415 can be detected by scanning for vulnerable Ruby on Rails versions.