← Back to CVEs
CVE-2016-10522
N/ADescription
rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.
CVE Details
CVSS v3.1 ScoreN/A
Published7/5/2018
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
rails_admin_project:rails_admin
Weaknesses (CWE)
CWE-352CWE-352
References
https://github.com/sferik/rails_admin/commit/b13e879eb93b661204e9fb5e55f7afa4f397537a(support@hackerone.com)
https://www.sourceclear.com/blog/Rails_admin-Vulnerability-Disclosure/(support@hackerone.com)
https://www.sourceclear.com/registry/security/cross-site-request-forgery-csrf-/ruby/sid-3173(support@hackerone.com)
https://github.com/sferik/rails_admin/commit/b13e879eb93b661204e9fb5e55f7afa4f397537a(af854a3a-2127-422b-91ae-364da2661108)
https://www.sourceclear.com/blog/Rails_admin-Vulnerability-Disclosure/(af854a3a-2127-422b-91ae-364da2661108)
https://www.sourceclear.com/registry/security/cross-site-request-forgery-csrf-/ruby/sid-3173(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.