CVE-2011-0446

medium
Published 2017-10-24 · Modified 2024-11-28
CVSS v3
CVSS v2
4.3
VIR risk
4.3

Description

Multiple cross-site scripting (XSS) vulnerabilities in the mail_to helper in Ruby on Rails before 2.3.11, and 3.x before 3.0.4, when javascript encoding is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) name or (2) email value.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2011-0446

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://groups.google.com/group/rubyonrails-security/msg/365b8a23b76a6b4a?dmode=source&output=gplain

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.3.11-0.1
debian debianbullseyefixed2.3.11-0.1
debian debianforkyfixed2.3.11-0.1
debian debiansidfixed2.3.11-0.1
debian debiantrixiefixed2.3.11-0.1

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsactionpack<~> 2.3.11~> 2.3.11
ruby RubyGemsactionview<~> 2.3.11~> 2.3.11
ruby RubyGemsactionpack<2.3.112.3.11
ruby RubyGemsactionpack>=3.0.0,<3.0.43.0.4
ruby RubyGemsactionview<2.3.112.3.11
ruby RubyGemsactionview>=3.0.0,<3.0.43.0.4

Application impact

VendorProductVersionsFixed
rubyonrailsrails2.0.0
rubyonrailsrails2.0.1
rubyonrailsrails2.0.2
rubyonrailsrails2.0.4
rubyonrailsrails2.1.0
rubyonrailsrails2.1.1
rubyonrailsrails2.1.2
rubyonrailsrails2.2.0
rubyonrailsrails2.2.1
rubyonrailsrails2.2.2
rubyonrailsrails2.3.2
rubyonrailsrails2.3.3
rubyonrailsrails2.3.4
rubyonrailsrails2.3.9
rubyonrailsrails2.3.10
rubyonrailsrails3.0.0
rubyonrailsrails3.0.1
rubyonrailsrails3.0.2
rubyonrailsrails3.0.3
rubyonrailsrails3.0.4

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.