Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-39308

18
FAUCET Score

CVE-2024-39308 is a medium-severity Cross-Site Scripting (XSS) vulnerability affecting RailsAdmin versions prior to 3.1.3 and 2.2.2. The flaw stems from improperly-escaped HTML in the list view's title attribute, allowing an authenticated attacker to inject malicious scripts. While the attack complexity is low and requires user interaction, the potential impact is limited to low confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.3.0CPE matchmatch criteria
cpe:2.3:a:rails_admin_project:rails_admin:*:*:*:*:*:ruby:*:*
>= 3.0.0, < 3.1.3CPE matchmatch criteria
cpe:2.3:a:rails_admin_project:rails_admin:*:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 3.0

6.8MEDIUM

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
4.0
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.58%
Probability of exploitation in next 30 days
EPSS Percentile
44.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0058 is in the 72nd percentile among its peer group of 15,225 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
rubygemspatch availablevia ghsa
Product: rails_adminFixed in: 3.1.3

Vendor Advisories (1)

rubygemsGHSA-8qgm-g2vv-vwvcmedium

RailsAdmin Cross-site Scripting vulnerability in the list view

Jul 8, 2024

References

github.com / railsadminteam/rails_admin/commit/b5a287d82e2cbd1737a1a01e11ede2911cce7fef
Patch
github.com / railsadminteam/rails_admin/commit/d84b39884059c4ed50197cec8522cca029a17673
Patch
github.com / railsadminteam/rails_admin/issues/3686
Issue Tracking
github.com / railsadminteam/rails_admin/security/advisories/GHSA-8qgm-g2vv-vwvc
Vendor Advisory
rubygems.org / gems/rails_admin/versions/2.3.0
Patch
rubygems.org / gems/rails_admin/versions/3.1.3
Patch