There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF). This could be exploited to read arbitrary local files if an attacker has access to exception messages.
CVSS
No CVSS.
References
Configurations
No configuration.
History
28 Mar 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-28 14:15
Updated : 2025-03-28 18:11
NVD link : CVE-2025-1781
Mitre link : CVE-2025-1781
CVE.ORG link : CVE-2025-1781
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference