CVE-2019-13714Code Injection in Google Chrome

CWE-94Code Injection8 documents8 sources
Severity
6.1MEDIUMNVD
EPSS
0.3%
top 45.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateMay 24

Description

Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

CVEListV5google/chromeunspecified78.0.3904.70
NVDgoogle/chrome< 78.0.3904.70
Debianchromium/chromium< 78.0.3904.87-1+3

🔴Vulnerability Details

3
GHSA
GHSA-xrw7-9m6r-77jp: Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 782022-05-24
OSV
CVE-2019-13714: Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 782019-11-25
CVEList
CVE-2019-13714: Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 782019-11-25

📋Vendor Advisories

3
Chrome
Stable Channel Update for Desktop: CVE-2019-137132019-10-22
Red Hat
chromium-browser: CSS injection2019-10-22
Debian
CVE-2019-13714: chromium - Insufficient validation of untrusted input in Color Enhancer extension in Google...2019

💬Community

1
Bugzilla
CVE-2019-13714 chromium-browser: CSS injection2019-10-23
CVE-2019-13714 — Code Injection in Google Chrome | cvebase