Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3432-fmrf-7vmh

Опубликовано: 28 мая 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Chrome PHP is missing encoding in CssSelector

Impact

CSS Selector expressions are not properly encoded, which can lead to XSS (cross-site scripting) vulnerabilities.

Patches

This is patched in v1.14.0.

Workarounds

Users can apply encoding manually to their selectors, if they are unable to upgrade.

Пакеты

Наименование

chrome-php/chrome

composer
Затронутые версииВерсия исправления

< 1.14.0

1.14.0

EPSS

Процентиль: 18%
0.00058
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
8 месяцев назад

Chrome PHP allows users to start playing with chrome/chromium in headless mode from PHP. Prior to version 1.14.0, CSS Selector expressions are not properly encoded, which can lead to XSS (cross-site scripting) vulnerabilities. This is patched in v1.14.0. As a workaround, users can apply encoding manually to their selectors if they are unable to upgrade.

EPSS

Процентиль: 18%
0.00058
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-79