CVE-2013-6415
Rails < 3.2.15 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
References (15)
Scores
EPSS
0.0151
EPSS Percentile
81.0%
Details
CWE
CWE-79
Status
published
Products (50)
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
... and 40 more
Published
Dec 07, 2013
Tracked Since
Feb 18, 2026