CVE-2019-20041: Input Validation
Published Dec 27, 2019
·Updated
wpksesbadprotocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
Affected Software
5 affected componentsFixes available
debian/wordpress
5.0.15+dfsg1-0+deb10u15.0.19+dfsg1-0+deb10u15.7.8+dfsg1-0+deb11u26.1.1+dfsg1-16.3.1+dfsg1-1
WordPress WordPress<5.3.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Event History
Dec 27, 2019
CVE Published
via MITRE·07:14 AM
Data Sourced
via MITRE·07:14 AM
Description
Frequently Asked Questions
1
What is CVE-2019-20041?
CVE-2019-20041 is a vulnerability in WordPress before 5.3.1 that allows attackers to bypass input sanitization.
2
What is the severity of CVE-2019-20041?
CVE-2019-20041 has a severity level of 9.8 (Critical).
3
How does CVE-2019-20041 affect WordPress?
CVE-2019-20041 affects WordPress versions before 5.3.1.
4
How can CVE-2019-20041 be exploited?
CVE-2019-20041 can be exploited by using the HTML5 colon named entity to bypass input sanitization.
5
How can I fix CVE-2019-20041?
To fix CVE-2019-20041, update WordPress to version 5.3.1 or later.