CVE-2020-36190

Cross-site Scripting in gem/rails_admin

Identifiers

CVE-2020-36190

Package Slug

gem/rails_admin

Vulnerability

Cross-site Scripting

Description

RailsAdmin (aka rails_admin) allows XSS via nested forms.

Affected Versions

All versions before 1.4.3, all versions starting from 2.0.0 before 2.0.2

Solution

Upgrade to versions 1.4.3, 2.0.2 or above.

Last Modified

2021-01-15

source