MEDIUM
A stored XSS issue was discovered in DAViCal through 1.1.8
Published Dec 4, 2019
5.4
MEDIUMCVSS 3.1
EPSS 1.13%
Description
A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users, making it possible for JavaScript stored in those fields to be executed by another (possibly privileged) user. Affected database fields include Username, Display Name, and Email.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://packetstormsecurity.com/files/155628/DAViCal-CalDAV-Server-1.1.8-Persistent-Cross-Site-Scripting.html x_refsource_MISCThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/17 mailing-listx_refsource_FULLDISCThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/18 mailing-listx_refsource_FULLDISCThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/19 mailing-listx_refsource_FULLDISCThird Party Advisory
- https://gitlab.com/davical-project/davical/blob/master/ChangeLog x_refsource_MISCRelease NotesThird Party Advisory
- https://hackdefense.com/publications/cve-2019-18347-davical-caldav-server-vulnerability/ x_refsource_MISCExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/12/msg00016.html mailing-listx_refsource_MLIST
- https://seclists.org/bugtraq/2019/Dec/30 mailing-listx_refsource_BUGTRAQ
- https://www.davical.org/ x_refsource_MISCProduct
- https://www.debian.org/security/2019/dsa-4582 vendor-advisoryx_refsource_DEBIAN
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 4, 2019
Updated Aug 5, 2024
Reserved Oct 23, 2019
Link CVE-2019-18347
CISA Vulnrichment
Updated n/a