Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.1 RubyGems

Haml vulnerable to cross-site scripting

GHSA-r53w-g4xm-3gc6 · CVE-2017-1002201

Published · Modified

Description

In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.

Ready to move

Start Securing

Free, no credit card | First findings in minutes