CVE-2023-23913

MEDIUM

Rails-ujs - XSS

Title source: llm
STIX 2.1

Description

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

Scores

CVSS v3 6.3
EPSS 0.0015
EPSS Percentile 35.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (4)
Rails/rails-ujs 5.1.0
Rails/rails-ujs 6.1.7.3
Rails/rails-ujs 7.0.4.3
rubygems/actionview 5.1.0 - 6.1.7.3RubyGems
Published Jan 09, 2025
Tracked Since Feb 18, 2026