CVE-2019-13714: Code Injection
Published Nov 25, 2019
·Updated
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
Affected Software
2 affected components
Google Chrome<78.0.3904.70
openSUSE Backports=15.0-sp1
Event History
Nov 25, 2019
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-13714?
CVE-2019-13714 is classified as a medium severity vulnerability.
2
How do I fix CVE-2019-13714?
To fix CVE-2019-13714, update Google Chrome to version 78.0.3904.70 or later.
3
What does CVE-2019-13714 affect?
CVE-2019-13714 affects Google Chrome and openSUSE Backports version 15.0-sp1.
4
What kind of exploit is associated with CVE-2019-13714?
CVE-2019-13714 allows remote attackers to inject CSS into HTML pages via a crafted URL.
5
When was CVE-2019-13714 discovered?
CVE-2019-13714 was disclosed in October 2019.