Description
** DISPUTED ** SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ad Inserter-Ad Manager & AdSense Ads Cross-Site Scripting (1.5.5)
MySQL CVE-2014-0386 Vulnerability (CVE-2014-0386)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29210)
WordPress Plugin Mobile browser color select Cross-Site Request Forgery (1.0.1)