CVE-2019-13714
published 2019-11-25CVE-2019-13714: Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an…
PriorityP424medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.83%
53.8th percentile
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| debian | chromium | < chromium 78.0.3904.87-1 (bookworm) | chromium 78.0.3904.87-1 (bookworm) |
| chrome | < 78.0.3904.70 | 78.0.3904.70 | |
| chrome | >= unspecified < 78.0.3904.70 | 78.0.3904.70 | |
| chrome_chrome | — | — | |
| opensuse | backports_sle | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2019-13713
vendor_chrome·2019-10-22·CVSS 6.5
CVE-2019-13713 [MEDIUM] Stable Channel Update for Desktop: CVE-2019-13713
Stable Channel Update for Desktop
CVE-2019-13713: Cross-origin data leak. Reported by David Erceg on 2019-08-13
[$2000][ 982812 ] Low CVE-2019-13714: CSS injection
Reported by Jun Kokatsu, Microsoft Browser Vulnerability Research on 2019-07-10
Severity: medium
Red Hat
chromium-browser: CSS injection
vendor_redhat·2019-10-22·CVSS 6.1
CVE-2019-13714 [MEDIUM] chromium-browser: CSS injection
chromium-browser: CSS injection
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
Debian
CVE-2019-13714: chromium - Insufficient validation of untrusted input in Color Enhancer extension in Google...
vendor_debian·2019·CVSS 6.1
CVE-2019-13714 [MEDIUM] CVE-2019-13714: chromium - Insufficient validation of untrusted input in Color Enhancer extension in Google...
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in 78.0.3904.87-1)
GHSA
GHSA-xrw7-9m6r-77jp: Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78
ghsa_unreviewed·2022-05-24
CVE-2019-13714 [MEDIUM] CWE-94 GHSA-xrw7-9m6r-77jp: Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
OSV
CVE-2019-13714: Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78
osv·2019-11-25·CVSS 6.1
CVE-2019-13714 [MEDIUM] CVE-2019-13714: Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00008.htmlhttps://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_22.htmlhttps://crbug.com/982812http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00008.htmlhttps://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_22.htmlhttps://crbug.com/982812
2019-11-25
Published