CVE-2015-7579 describes a cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem versions 1.0.2, affecting Ruby on Rails 4.2.x and 5.x. This flaw allows remote attackers to inject arbitrary web script or HTML due to improper handling of HTML entities by the Rails::Html::FullSanitizer class. With a CVSS score of 6.1 (Medium), exploitation requires user interaction (UI:R) but can be executed with low attack complexity (AC:L) over the network (AV:N), potentially leading to limited confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.2CPE matchmatch criteria | cpe:2.3:a:rubyonrails:html_sanitizer:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.