VDB
CVE-2020-13756
CVE-2020-13756
PUBLISHED
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.
EPSS 27.85% · 96.6th percentile
Risk Scores
EPSS Score
27.85%
96.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:16.04:LTS | php-horde-css-parser | 1.0.7-1, 1.0.7-2, 1.0.8-1 |
| Ubuntu:Pro:18.04:LTS | php-horde-css-parser | 0, 1.0.11-1ubuntu1, 1.0.11-1 |
Exploit Intelligence
- Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE) (github-poc-repo)
- Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE) (github-poc-repo)
- Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE) (github-poc-repo)
- Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE) (github-poc-repo)
- Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE) (github-poc-repo)
- Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE) (github-poc-repo)
- Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE) (github-poc-repo)
- Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE) (github-poc-repo)
- Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE) (github-poc-repo)
- Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE) (github-poc)
…and 22 more exploits
Timeline
- Jun 3, 2020 PoC Published
- Jun 3, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 12, 2022 VulnCheck KEV Exploitation
- Feb 28, 2022 EPSS Score
- May 1, 2022 EPSS Score
- May 11, 2022 VulnCheck KEV Exploitation
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-13756 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-13756 third-party-advisory
- https://github.com/MyIntervals/PHP-CSS-Parser/commit/2ebf59e8bfbf6cfc1653a5f0ed743b95062c62a4 third-party-advisory
- https://ubuntu.com/security/notices/USN-7502-1 vendor-advisory