Description
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
Remediation
References
Related Vulnerabilities
MySQL Divide By Zero Vulnerability (CVE-2019-16168)
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.22)
WordPress Plugin SS Downloads Multiple Cross-Site Scripting Vulnerabilities (1.4.4.1)
WordPress Plugin WP Limit Login Attempts Security Bypass (2.6.4)
Django URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-7234)