Releases99
Frequency1 month 3 weeks
Last Release
Downloads48.8M
The administration framework for Ruby on Rails.

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM

The Active Admin (aka activeadmin) framework before 3.2.2 for Ruby on Rails allows stored XSS in certain situations where users can create entities (to be later edited in forms) with arbitrary names, aka a "dynamic form legends" issue. 4.0.0.beta7 is also a fixed version.