Логотип exploitDog
bind:CVE-2019-18345
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-18345

Количество 5

Количество 5

ubuntu логотип

CVE-2019-18345

больше 5 лет назад

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2019-18345

больше 5 лет назад

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.

CVSS3: 9.3
EPSS: Низкий
debian логотип

CVE-2019-18345

больше 5 лет назад

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echo ...

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-27vg-v28w-gqgh

около 3 лет назад

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.

CVSS3: 9.3
EPSS: Низкий
fstec логотип

BDU:2020-01982

больше 5 лет назад

Уязвимость сервера обмена календарями DAViCal, связанная с недостатками используемых мер по защите структур веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-18345

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.

CVSS3: 9.3
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-18345

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.

CVSS3: 9.3
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-18345

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echo ...

CVSS3: 9.3
1%
Низкий
больше 5 лет назад
github логотип
GHSA-27vg-v28w-gqgh

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.

CVSS3: 9.3
1%
Низкий
около 3 лет назад
fstec логотип
BDU:2020-01982

Уязвимость сервера обмена календарями DAViCal, связанная с недостатками используемых мер по защите структур веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.4
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу