---
cve: "CVE-2013-4492"
severity: "LOW"
cvss: 3.1
epss: "2.2%"
vendor: "n/a"
kev: false
exploited: false
published: "2013-12-07 00:00:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T11:18:29+02:00"
---

# CVE-2013-4492

> 3.1 LOW · 🧪 PoC

## Beschreibung

Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.

## Referenzen

- <http://lists.opensuse.org/opensuse-updates/2013-12/msg00093.html>
- <http://www.securityfocus.com/bid/64076>
- <https://groups.google.com/forum/message/raw?msg=ruby-security-ann/pLrh6DUw998/bLFEyIO4k_EJ>
- <http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/>
- <http://www.debian.org/security/2013/dsa-2830>
- <https://github.com/svenfuchs/i18n/commit/92b57b1e4f84adcdcc3a375278f299274be62445>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2013-4492) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
