CVE Database
/

CVE-2018-3740

Back to search

CVE-2018-3740

Published: Mar 30, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.

VendorProductVersions

Ryan Grove

sanitize (ruby gem)

affected
< 4.6.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now