Back to Database
Status published
Medium
CVE-2020-4070
Cross-site Scripting in CSS Validator
Vulnerability Description
In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-4070
Credits & Attribution
No credits recorded in the NVD database.
Affected Vendor
World Wide Web Consortium (W3C)
View all reports →Affected Software
CSS Validator
Vulnerable Versions:
<= 54d68a1
Timeline
Official Publish:
June 22nd, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N