216.73.217.22

CVE-2025-1781

· Published 28/03/2025 14:15 · Modified 28/03/2025 18:11

Labels: CVE-2025-1781 2025-03-28CVE-2025-1781CWE-611[email protected]

Essential information

Published
28/03/2025 14:15
Modified
28/03/2025 18:11
Author
Creator
CVSS
8.4 HIGH (v3) 8.4 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF).  This could be exploited to read arbitrary local files if an attacker has access to exception messages.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
w3css / w3css validator cpe:2.3:a:w3css:w3css_validator:<cssval-20250226:*:*:*:*:*:*:*

References