Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-06441
HistoryJan 29, 2024 - 12:00 a.m.

WebCalendar Cross-Site Scripting Vulnerability

2024-01-2900:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
webcalendar
php
xss
vulnerability
edit_entry.php

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

21.7%

WebCalendar is a PHP application for maintaining calendars for individual users or groups of Intranet users. It can also be configured as an event calendar. WebCalendar v1.3.0 suffers from a cross-site scripting vulnerability that stems from the lack of effective filtering and escaping of user-supplied data in the /WebCalendarvqsmnseug2/edit_entry.php component, which can be exploited by an attacker to execute arbitrary web script or HTML by injecting a carefully crafted payload.

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

21.7%

Related for CNVD-2024-06441