A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sanitize_project | sanitize | * |