CVE-2019-18347
5.4
MEDIUM
CVSS 3.1
EPSS 1.1%
Description
A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users, making it possible for JavaScript stored in those fields to be executed by another (possibly privileged) user. Affected database fields include Username, Display Name, and Email.
How to fix CVE-2019-18347
To remediate CVE-2019-18347, upgrade the affected package to a fixed version below.
- Debian/davical—upgrade to 1.1.9.2-1 or later
Is CVE-2019-18347 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.1.9.2-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |