Back to Database
Status published
Medium
CVE-2010-3933
Ruby on Rails 2.3.9 and 3.0.0 does not properly handle...
Vulnerability Description
Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-3933
Credits & Attribution
No credits recorded in the NVD database.
References
More from rubyonrails
View All →CVE-2025-54314
Thor before 1.4.0 can construct an unsafe shell command from...
Low
2.8
CVE-2019-25025
The activerecord-session_store (aka Active Record Session Store) component through 1.1.3...
Medium
5.3
CVE-2017-17920
SQL injection vulnerability in the 'reorder' method in Ruby on...
High
8.1
CVE-2017-17919
SQL injection vulnerability in the 'order' method in Ruby on...
Unknown
0
CVE-2017-17917
SQL injection vulnerability in the 'where' method in Ruby on...
High
8.1
Affected Vendor
rubyonrails
View all reports →Affected Software
rails
Vulnerable Versions:
2.3.9, 3.0.0
Timeline
Official Publish:
October 27th, 2010
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.