Описание
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCalendar VTODO entries via raw string concatenation without applying RFC 5545 TEXT value escaping. User-controlled task titles containing CRLF characters break the iCalendar property boundary, allowing injection of arbitrary iCalendar properties such as ATTACH, VALARM, or ORGANIZER. This vulnerability is fixed in 2.3.0.
Ссылки
- Issue Tracking
- Release Notes
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.0 (исключая)
cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
EPSS
Процентиль: 9%
0.00196
Низкий
4.1 Medium
CVSS3
Дефекты
CWE-93
Связанные уязвимости
CVSS3: 4.1
github
5 месяцев назад
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output
EPSS
Процентиль: 9%
0.00196
Низкий
4.1 Medium
CVSS3
Дефекты
CWE-93