CVE-2022-4522

A vulnerability classified as problematic was found in CalendarXP up to 10.0.1. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 10.0.2 is able to address this issue. The name of the patch is e3715b2228ddefe00113296069969f9e184836da. It is recommended to upgrade the affected component. VDB-215902 is the identifier assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:calendarxp:calendarxp:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : 3.5
References () https://github.com/victorwon/calendarxp/commit/e3715b2228ddefe00113296069969f9e184836da - Patch, Third Party Advisory () https://github.com/victorwon/calendarxp/commit/e3715b2228ddefe00113296069969f9e184836da - Patch, Third Party Advisory
References () https://github.com/victorwon/calendarxp/releases/tag/10.0.2 - Third Party Advisory () https://github.com/victorwon/calendarxp/releases/tag/10.0.2 - Third Party Advisory
References () https://vuldb.com/?id.215902 - Third Party Advisory () https://vuldb.com/?id.215902 - Third Party Advisory
Summary
  • (es) Una vulnerabilidad fue encontrada en CalendarXP hasta 10.0.1 y clasificada como problemática. Esta vulnerabilidad afecta a código desconocido. La manipulación conduce a Cross-Site Scripting. El ataque se puede iniciar de forma remota. La actualización a la versión 10.0.2 puede solucionar este problema. El nombre del parche es e3715b2228ddefe00113296069969f9e184836da. Se recomienda actualizar el componente afectado. VDB-215902 es el identificador asignado a esta vulnerabilidad.

Information

Published : 2022-12-15 21:15

Updated : 2024-11-21 07:35


NVD link : CVE-2022-4522

Mitre link : CVE-2022-4522

CVE.ORG link : CVE-2022-4522


JSON object : View

Products Affected

calendarxp

  • calendarxp
CWE
CWE-707

Improper Neutralization