CVE-2024-32464: Rails Actiontext Unsanitized Attachment Content
Action Text attachments are missing sanitization on their content attribute before rendering. This missing validation boundary allows Cross-Site Scripting (XSS) via specially crafted tags with malicious HTML in the content attribute.
Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Rubyβ
greprules fetch cve-2024-32464-rails-actiontext-unsanitized-attachment-content --engine opengrepDescription
Action Text attachments are missing sanitization on their content attribute before rendering. This missing validation boundary allows Cross-Site Scripting (XSS) via specially crafted tags with malicious HTML in the content attribute.
Community feedback
0 signals from signed-in users.
- Useful
- 0
- False positive
- 0
- Metadata
- 0