Chrome PHP allows users to start playing with chrome/chromium in headless mode from PHP. Prior to version 1.14.0, CSS Selector expressions are not properly encoded, which can lead to XSS (cross-site scripting) vulnerabilities. This is patched in v1.14.0. As a workaround, users can apply encoding manually to their selectors if they are unable to upgrade.
History

Fri, 30 May 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 May 2025 19:00:00 +0000

Type Values Removed Values Added
Description Chrome PHP allows users to start playing with chrome/chromium in headless mode from PHP. Prior to version 1.14.0, CSS Selector expressions are not properly encoded, which can lead to XSS (cross-site scripting) vulnerabilities. This is patched in v1.14.0. As a workaround, users can apply encoding manually to their selectors if they are unable to upgrade.
Title Chrome PHP is missing encoding in `CssSelector`
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-30T18:47:42.853Z

Updated: 2025-05-30T20:39:45.976Z

Reserved: 2025-05-27T20:14:34.296Z

Link: CVE-2025-48883

cve-icon Vulnrichment

Updated: 2025-05-30T20:39:41.312Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-30T19:15:29.540

Modified: 2025-06-02T17:32:17.397

Link: CVE-2025-48883

cve-icon Redhat

No data.