First published: Mon Nov 25 2019(Updated: )
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <78.0.3904.70 | |
openSUSE Backports | =15.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13714 is classified as a medium severity vulnerability.
To fix CVE-2019-13714, update Google Chrome to version 78.0.3904.70 or later.
CVE-2019-13714 affects Google Chrome and openSUSE Backports version 15.0-sp1.
CVE-2019-13714 allows remote attackers to inject CSS into HTML pages via a crafted URL.
CVE-2019-13714 was disclosed in October 2019.