ankane

3 exploits Active since Jun 2019
CVE-2019-12732 WRITEUP MEDIUM WRITEUP
Chartkick < 3.1.0 - XSS
The Chartkick gem through 3.1.0 for Ruby allows XSS.
CVSS 4.7
CVE-2020-16253 WRITEUP HIGH WRITEUP
Pghero < 2.6.0 - CSRF
The PgHero gem through 2.6.0 for Ruby allows CSRF.
CVSS 8.1
CVE-2020-16254 WRITEUP MEDIUM WRITEUP
Chartkick < 3.3.2 - Injection
The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).
CVSS 6.1