Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving generated pagination links.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mislav_marohnic | will_paginate | 3.0 |
| mislav_marohnic | will_paginate | 3.0.2 |
| mislav_marohnic | will_paginate | 3.0.1 |
| mislav_marohnic | will_paginate | 3.0.3 |
| mislav_marohnic | will_paginate | * |