Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-1097

Опубликовано: 15 нояб. 2024
Источник: nvd
CVSS3: 7.6
CVSS3: 5.4
EPSS Низкий

Описание

A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. An attacker can inject malicious scripts, which are then executed in the context of other users who view the report, potentially leading to the theft of user accounts and cookies.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:k5n:webcalendar:1.3.0:*:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.00174
Низкий

7.6 High

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 7.6
github
около 1 года назад

A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. An attacker can inject malicious scripts, which are then executed in the context of other users who view the report, potentially leading to the theft of user accounts and cookies.

EPSS

Процентиль: 39%
0.00174
Низкий

7.6 High

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79