In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9.
2020-06-22T16:15:11.963
2024-11-21T05:32:15.050
Modified
CVSSv3.1: 4.6 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | w3c | css_validator | ≤ 2020-01-19 | Yes |