Vulnerability CVE-2020-13756


Published: 2020-06-03

Description:
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Sabberworm -> Php css parser 

 References:
http://packetstormsecurity.com/files/157923/Sabberworm-PHP-CSS-Code-Injection.html
http://seclists.org/fulldisclosure/2020/Jun/7
https://github.com/sabberworm/PHP-CSS-Parser/commit/2ebf59e8bfbf6cfc1653a5f0ed743b95062c62a4
https://github.com/sabberworm/PHP-CSS-Parser/releases/tag/8.3.1

Copyright 2024, cxsecurity.com

 

Back to Top