-
CVSS Score
-The vulnerability is directly associated with the function Xapian::MSet::snippet() as described in the provided descriptions and references. The function's role in processing input and generating output makes it a critical point for XSS vulnerabilities. The fix for the vulnerability involves modifying this function to properly escape HTML, confirming its status as the vulnerable component.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| xapian-core | rubygems | < 1.4.6 | 1.4.6 |