First published: Wed Jun 03 2020(Updated: )
Code injection vulnerability in allSelectors()
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/sabberworm/php-css-parser | >=8.3.0<8.3.1>=8.2.0<8.2.1>=8.1.0<8.1.1>=8.0.0<8.0.1>=7.0.0<7.0.4>=6.0.0<6.0.2>=5.2.0<5.2.1>=5.1.0<5.1.3>=5.0.0<5.0.9>=4.0.0<4.0.1>=3.0.0<3.0.1>=2.0.0<2.0.1>=1.0.0<1.0.1 | |
composer/sabberworm/php-css-parser | >=1.0.0<1.0.1 | 1.0.1 |
composer/sabberworm/php-css-parser | >=2.0.0<2.0.1 | 2.0.1 |
composer/sabberworm/php-css-parser | >=3.0.0<3.0.1 | 3.0.1 |
composer/sabberworm/php-css-parser | >=4.0.0<4.0.1 | 4.0.1 |
composer/sabberworm/php-css-parser | >=5.0.0<5.0.9 | 5.0.9 |
composer/sabberworm/php-css-parser | >=5.1.0<5.1.3 | 5.1.3 |
composer/sabberworm/php-css-parser | >=5.2.0<5.2.1 | 5.2.1 |
composer/sabberworm/php-css-parser | >=6.0.0<6.0.2 | 6.0.2 |
composer/sabberworm/php-css-parser | >=7.0.0<7.0.4 | 7.0.4 |
composer/sabberworm/php-css-parser | >=8.0.0<8.0.1 | 8.0.1 |
composer/sabberworm/php-css-parser | >=8.1.0<8.1.1 | 8.1.1 |
composer/sabberworm/php-css-parser | >=8.2.0<8.2.1 | 8.2.1 |
composer/sabberworm/php-css-parser | >=8.3.0<8.3.1 | 8.3.1 |
Sabberworm PHP CSS Parser | <8.3.1 | |
debian/php-horde-css-parser | <=1.0.11-8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13756 is a code injection vulnerability in the allSelectors() function of Sabberworm PHP CSS Parser.
CVE-2020-13756 allows for remote code execution when the allSelectors() or getSelectorsBySpecificity() functions are called with input from an attacker.
CVE-2020-13756 has a severity rating of 9.8 (Critical) out of 10.0.
Sabberworm PHP CSS Parser versions 8.3.0 to 8.3.1, 8.2.0 to 8.2.1, 8.1.0 to 8.1.1, 8.0.0 to 8.0.1, 7.0.0 to 7.0.4, 6.0.0 to 6.0.2, 5.2.0 to 5.2.1, 5.1.0 to 5.1.3, 5.0.0 to 5.0.9, 4.0.0 to 4.0.1, 3.0.0 to 3.0.1, 2.0.0 to 2.0.1, and 1.0.0 are all affected by CVE-2020-13756.
To fix CVE-2020-13756, update the Sabberworm PHP CSS Parser package to version 8.3.1, 8.2.1, 8.1.1, 8.0.1, 7.0.4, 6.0.2, 5.2.1, 5.1.3, 5.0.9, 4.0.1, 3.0.1, 2.0.1, or 1.0.1.