Lucene search

K
osvGoogleOSV:CVE-2019-20041
HistoryDec 27, 2019 - 8:15 a.m.

CVE-2019-20041

2019-12-2708:15:09
Google
osv.dev
14

AI Score

6.6

Confidence

Low

EPSS

0.009

Percentile

82.5%

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

AI Score

6.6

Confidence

Low

EPSS

0.009

Percentile

82.5%