
CVE-2022-22682
https://notcve.org/view.php?id=CVE-2022-22682
12 Jul 2022 — Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.4.5-10930 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Una neutralización inapropiada de la entrada durante la generación de páginas web ("Cross-site Scripting") es una vulnerabilidad en la administración de eventos en Synology Calendar versiones anteriores a 2.4.5-10930, que permite a usuarios remotos autent... • https://www.synology.com/security/advisory/Synology_SA_22_07 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-33705
https://notcve.org/view.php?id=CVE-2022-33705
11 Jul 2022 — Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission. Una exposición de información en Calendar versiones anteriores a 12.3.05.10000, permite a un atacante acceder a la programación del calendario sin el permiso READ_CALENDAR • https://security.samsungmobile.com/serviceWeb.smsb?year==2022&month=07 • CWE-285: Improper Authorization •

CVE-2022-24838 – Command Injection in Appointment Emails for Nextcloud Calendar
https://notcve.org/view.php?id=CVE-2022-24838
11 Apr 2022 — Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON request, a malicious attacker can inject newlines to break out of the `RCPT TO:

CVE-2021-34812
https://notcve.org/view.php?id=CVE-2021-34812
18 Jun 2021 — Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitive information via unspecified vectors. La vulnerabilidad del uso de credenciales codificadas en el componente php de Synology Calendar anterior a la versión 2.4.0-0761 permite a los atacantes remotos obtener información confidencial a través de vectores no especificados • https://www.synology.com/security/advisory/Synology_SA_21_12 • CWE-798: Use of Hard-coded Credentials •

CVE-2019-11829
https://notcve.org/view.php?id=CVE-2019-11829
30 Jun 2019 — OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-Real-IP' header. Una vulnerabilidad de inyección de comandos del sistema operativo en el archivo drivers_syno_import_user.php en Synology Calendar anterior a versión 2.3.1-0617, permite a los atacantes remotos ejecutar comandos arbitrarios por medio del encabezado “X-Real-IP” creado. • https://www.synology.com/security/advisory/Synology_SA_19_12 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2019-11825
https://notcve.org/view.php?id=CVE-2019-11825
30 Jun 2019 — Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers to inject arbitrary web script or HTML via the title parameter. Una vulnerabilidad de tipo cross-site scripting (XSS) en el Editor de eventos en Synology Calendar anterior a versión 2.3.0-0615, permite a los atacantes remotos inyectar script web o HTML arbitrario por medio del parámetro title. • https://www.synology.com/security/advisory/Synology_SA_19_04 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-11820
https://notcve.org/view.php?id=CVE-2019-11820
09 May 2019 — Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cmdline. La exposición a la información a través de la vulnerabilidad del entorno de procesos en Synology Calendar, versiones anteriores a 2.3.3-0620, permite a los usuarios locales obtener credenciales a través de cmdline. • https://www.synology.com/security/advisory/Synology_SA_19_21 • CWE-522: Insufficiently Protected Credentials •

CVE-2018-13299
https://notcve.org/view.php?id=CVE-2018-13299
01 Apr 2019 — Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter. Una vulnerabilidad de salto de directorio relativo en el actualizador de adjuntos en Synology Calendar, en versiones anteriores a la 2.2.2-0532, permite a los usuarios remotos autenticados subir archivos arbitrarios mediante el parámetro "filename". • https://www.synology.com/security/advisory/Synology_SA_18_54 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-23: Relative Path Traversal •

CVE-2018-18872 – Calendar <= 1.3.10 - Authenticated Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2018-18872
30 Oct 2018 — The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin/admin.php?page=calendar add action, or the category name during category creation at the wp-admin/admin.php?page=calendar-categories URI. Kieran O'Shea Calendar plugin anterior a la versión 1.3.11 para WordPress, tiene un XSS guardado mediante el parámetro event_title en un archivo wp-admin/admin.php?Page=calendar agrega acción, o el nombre de la categoría durante la creación de la catego... • https://wpvulndb.com/vulnerabilities/9141 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-3763
https://notcve.org/view.php?id=CVE-2018-3763
05 Jul 2018 — In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins. En Nextcloud Calendar en versiones anteriores a la 1.5.8 y la 1.6.1, la falta de saneamiento de los resultados de búsqueda de un campo de autocompletar podría conducir a Cross-Site Scripting... • https://nextcloud.com/security/advisory/?id=nc-sa-2018-004 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •