Description
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.
Remediation
References
Related Vulnerabilities
Joomla Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2018-11325)
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6146)
Oracle Database Server CVE-2009-1995 Vulnerability (CVE-2009-1995)
Oracle Database Server CVE-2011-0852 Vulnerability (CVE-2011-0852)