Geminabox contains Cross-site Scripting
Moderate severity
GitHub Reviewed
Published
Nov 29, 2017
to the GitHub Advisory Database
•
Updated Mar 14, 2023
Description
Published to the GitHub Advisory Database
Nov 29, 2017
Reviewed
Jun 16, 2020
Last updated
Mar 14, 2023
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb.
References