VDB
CVE-2020-13756
CVE-2020-13756
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.
EPSS 55.08% · 98.9th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
55.08%
98.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:16.04:LTS | php-horde-css-parser | 1.0.7-1, 1.0.7-2, 1.0.8-1 |
| Ubuntu:Pro:18.04:LTS | php-horde-css-parser | 0, 1.0.11-1ubuntu1, 1.0.11-1 |
Timeline
- Jun 3, 2020 PoC Published
- Jun 3, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 12, 2022 VulnCheck KEV Exploitation
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- May 11, 2022 VulnCheck KEV Exploitation
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-13756 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-13756 third-party-advisory
- https://github.com/MyIntervals/PHP-CSS-Parser/commit/2ebf59e8bfbf6cfc1653a5f0ed743b95062c62a4 third-party-advisory
- https://ubuntu.com/security/notices/USN-7502-1 vendor-advisory