Lucene search

K
cve[email protected]CVE-2023-46784
HistoryMay 17, 2024 - 9:15 a.m.

CVE-2023-46784

2024-05-1709:15:10
CWE-918
CWE-22
web.nvd.nist.gov
57
cve-2023-46784
reserved
upcoming
security problem
announcement
nvd

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.6%

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’), Server-Side Request Forgery (SSRF) vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Absolute Path Traversal, : Server Side Request Forgery.This issue affects ICS Calendar: from n/a through 10.12.0.3.

Affected configurations

Vulners
Node
room_34_creative_services\,_llcics_calendarRange10.12.0.3

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "ics-calendar",
    "product": "ICS Calendar",
    "vendor": "Room 34 Creative Services, LLC",
    "versions": [
      {
        "changes": [
          {
            "at": "10.12.0.4",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "10.12.0.3",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.6%