CVE-2019-18347 Information
Description
A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users making it possible for JavaScript stored in those fields to be executed by another (possibly privileged) user. Affected database fields include Username Display Name and Email.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
http://packetstormsecurity.com/files/155628/DAViCal-CalDAV-Server-1.1.8-Persistent-Cross-Site-Scripting.html http://seclists.org/fulldisclosure/2019/Dec/17 http://seclists.org/fulldisclosure/2019/Dec/18 http://seclists.org/fulldisclosure/2019/Dec/19 https://gitlab.com/davical-project/davical/blob/master/ChangeLog https://hackdefense.com/publications/cve-2019-18347-davical-caldav-server-vulnerability/ https://lists.debian.org/debian-lts-announce/2019/12/msg00016.html https://seclists.org/bugtraq/2019/Dec/30 https://www.davical.org/ https://www.debian.org/security/2019/dsa-4582
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: