Логотип exploitDog
bind:CVE-2020-25817
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-25817

Количество 2

Количество 2

nvd логотип

CVE-2020-25817

больше 4 лет назад

SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user submitted data in custom project code, it can lead to vulnerabilities such as XSS on HTML output rendered through this custom code. This is now mitigated by disabling external entities during parsing. (The correct CVE ID year is 2020 [CVE-2020-25817, not CVE-2021-25817]).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3vjc-5x79-m9r8

больше 3 лет назад

SilverStripe XXE Vulnerability in CSSContentParser

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-25817

SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user submitted data in custom project code, it can lead to vulnerabilities such as XSS on HTML output rendered through this custom code. This is now mitigated by disabling external entities during parsing. (The correct CVE ID year is 2020 [CVE-2020-25817, not CVE-2021-25817]).

CVSS3: 4.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3vjc-5x79-m9r8

SilverStripe XXE Vulnerability in CSSContentParser

CVSS3: 4.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу