CVE-2020-13756
03.06.2020, 14:15
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.
| Vendor | Product | Version |
|---|---|---|
| sabberworm | php_css_parser | 𝑥 < 8.3.1 |
𝑥
= Vulnerable software versions
References