CVE-2016-10548
MEDIUMreduce-css-calc <=1.2.4 - Arbitrary Code Execution via Crafted CSS Input
Title source: llmDescription
Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on the client and arbitrary code injection possible on the server and user input is passed to the `calc` function.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://gist.github.com/ChALkeR/415a41b561ebea9b341efbb40b802fc9
Exploit, Third Party Advisory x_refsource_misc
https://nodesecurity.io/advisories/144
Scores
CVSS v3
6.1
EPSS
0.0121
EPSS Percentile
64.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
CWE-94
Status
published
Products (2)
npm/reduce-css-calc
0 - 1.2.5npm
reduce-css-calc_project/reduce-css-calc
< 1.2.4
Published
May 31, 2018
Tracked Since
Feb 18, 2026