CVE Database
/

CVE-2016-10522

Back to search

CVE-2016-10522

Published: Jul 5, 2018

Modified: Aug 6, 2024

PUBLISHED

Description

rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.

VendorProductVersions

https://github.com/sferik

rails_admin ruby gem

affected
>= 1.1.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now