Description
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
Exploits (12)
exploitdb
WORKING POC
by NotoriousRebel · pythonwebappsmultiple
https://www.exploit-db.com/exploits/46585
Nuclei Templates (1)
Rails File Content Disclosure
HIGHby omarkurt
Shodan:
cpe:"cpe:2.3:a:rubyonrails:rails"
References (14)
Scores
CVSS v3
7.5
EPSS
0.9432
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Lab Environment
COMMUNITY
Community Lab
+8 more repos
Details
CISA KEV
2025-07-07
VulnCheck KEV
2025-07-07
ENISA EUVD
EUVD-2019-0375
CWE
CWE-22
Status
published
Products (8)
debian/debian_linux
8.0
fedoraproject/fedora
30
opensuse/leap
15.0
redhat/cloudforms
4.7
redhat/cloudforms
4.6
redhat/software_collections
1.0
rubygems/actionview
5.2.0 - 5.2.2.1RubyGems
rubyonrails/rails
3.0.0 - 4.2.11.1
Published
Mar 27, 2019
KEV Added
Jul 07, 2025
Tracked Since
Feb 18, 2026