Description
Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on the client and arbitrary code injection possible on the server and user input is passed to the `calc` function.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0196 | Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on the client and arbitrary code injection possible on the server and user input is passed to the `calc` function. |
Github GHSA |
GHSA-4662-j96g-mv46 | Arbitrary Code Injection in reduce-css-calc |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-16T20:03:43.284Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2016-10548
No data.
Status : Modified
Published: 2018-05-31T20:29:01.783
Modified: 2024-11-21T02:44:14.537
Link: CVE-2016-10548
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA