Home
MEDIUM: 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before 2.15
affected
Description
The Mocca Calendar application before 2.15 for XWiki allows XSS via a title to the view event page.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Any version before 2.15
References
github.com/xwikisas/application-mocca-calendar
github.com/...lendar/security/advisories/GHSA-fjv4-pgh9-jfgc
extensions.xwiki.org/xwiki/bin/view/Extension/MoccaCalendar
github.com/xwiki-contrib/application-mocca-calendar