CVE-2019-20041

CRITICAL WAF: Medium
CVSS 9.8 Published: 2019-12-27
CWE-20

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

WAF Coverage Analysis

Improper Input Validation Medium WAF Coverage

OWASP: A03:2021 Injection

920xxx - Protocol Enforcement 941xxx - XSS / XXE 942xxx - SQL Injection

Affected Software

VendorProductVersion
wordpresswordpressup to 5.3.1
debiandebian_linux8.0
debiandebian_linux9.0
debiandebian_linux10.0

References

Back to CVE Database