CVE-2016-10548

MEDIUM

reduce-css-calc <=1.2.4 - Arbitrary Code Execution via Crafted CSS Input

Title source: llm
STIX 2.1

Description

Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on the client and arbitrary code injection possible on the server and user input is passed to the `calc` function.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://gist.github.com/ChALkeR/415a41b561ebea9b341efbb40b802fc9
Exploit, Third Party Advisory x_refsource_misc
https://nodesecurity.io/advisories/144

Scores

CVSS v3 6.1
EPSS 0.0121
EPSS Percentile 64.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79 CWE-94
Status published
Products (2)
npm/reduce-css-calc 0 - 1.2.5npm
reduce-css-calc_project/reduce-css-calc < 1.2.4
Published May 31, 2018
Tracked Since Feb 18, 2026