Home
MEDIUM: 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before 2.15
affected
Description
The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 2.15
References
github.com/...lendar/security/advisories/GHSA-jvq4-j2qw-q7x2
github.com/xwikisas/application-mocca-calendar
extensions.xwiki.org/xwiki/bin/view/Extension/MoccaCalendar
github.com/xwiki-contrib/application-mocca-calendar