CVE-2013-6416: XSS
Cross-site scripting (XSS) vulnerability in the simpleformat helper in actionpack/lib/actionview/helpers/texthelper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
Other sources
Cross-site scripting (XSS) vulnerability in the simpleformat helper in actionpack/lib/actionview/helpers/texthelper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/actionpackto a version that resolves this vulnerability.Fixed in 4.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6416?
CVE-2013-6416 is considered a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2013-6416?
To resolve CVE-2013-6416, upgrade to Ruby on Rails version 4.0.2 or later.
What systems are affected by CVE-2013-6416?
CVE-2013-6416 affects Ruby on Rails versions 4.0.0 to 4.0.1 and all beta and release candidate versions of 4.0.0.
What type of vulnerability is CVE-2013-6416?
CVE-2013-6416 is classified as a cross-site scripting (XSS) vulnerability in the simple_format helper.
Can CVE-2013-6416 lead to data theft?
Yes, if exploited, CVE-2013-6416 can allow remote attackers to inject arbitrary scripts, potentially leading to data theft.