CVE-2020-4070

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
22/06/2020
Last modified:
30/06/2020

Description

In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:w3c:css_validator:*:*:*:*:*:*:*:* 2020-01-19 (including)