CVE Published: 22/06/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: GitHub_M |
Vendor: World Wide Web Consortium (W3C) |
Product: CSS Validator Status : PUBLISHED
CVE-2020-4070 Description
In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9.
Metrics
CVSS Version: 3.1 |
Base Score: 4.6 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CWE-ID: CWE-79 CWE Name: CWE-79: Improper Neutralization of Input During Web Page Generation (
Cross-site Scripting
) Source: World Wide Web Consortium (W3C)
Common Attack Pattern Enumeration and Classification (CAPEC)