Description
Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://vuln.ryotak.me/advisories/51
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/whiteleaf7/narou/blob/develop/ChangeLog.md#380-20210627
Scores
CVSS v3
9.8
EPSS
0.0051
EPSS Percentile
66.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (2)
narou_project/narou
< 3.8.0
rubygems/narou
0 - 3.8.0RubyGems
Published
Jun 28, 2021
Tracked Since
Feb 18, 2026