Page 5 of 26 results (0.014 seconds)

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) cal_id or (2) original_cal_id parameter. Vulnerabilidad de autorización indebida en SYNO.Cal.Event en Calendar en versiones anteriores a la 2.1.2-0511 permite que usuarios remotos autenticados creen eventos arbitrarios mediante los parámetros (1) cal_id o (2) original_cal_id. • https://www.synology.com/en-global/support/security/Synology_SA_18_16 • CWE-863: Incorrect Authorization •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar before 2.1.1-0502 allows remote authenticated users to inject arbitrary web script or HTML via title parameter. Vulnerabilidad de Cross-Site Scripting (XSS) en Notification Center en Synology Calendar en versiones anteriores a la 2.1.1-0502 permite que atacantes remotos autenticados inyecten scripts web o HTML arbitrarios mediante el parámetro title. • https://www.synology.com/en-global/support/security/Synology_SA_18_06 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

The Mail.ru Calendar plugin before 2.5.0.61 for Atlassian Jira has XSS via the Name field in a Create Calender action, related to a MailRuCalendar.jspa#period/month URI. El plugin Mail.ru Calendar, en versiones anteriores a la 2.5.0.61, en Atlassian Jira tiene Cross-Site Scripting (XSS) mediante el campo Name en una acción Create Calender. Esto se relaciona con un URI MailRuCalendar.jspa#period/month. • https://marketplace.atlassian.com/plugins/ru.mail.jira.plugins.mailrucal/versions https://packetstormsecurity.com/files/137649/JIRA-Mail.ru-Calendar-2.4.2.50_JIRA6-Cross-Site-Scripting.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors. Vulnerabilidad de control de acceso indebido en SYNO.Cal.EventBase en Synology Calendar en versiones anteriores a la 2.0.1-0242 permite que usuarios remotos autenticados modifiquen eventos del calendario mediante vectores sin especificar. • https://www.synology.com/en-global/support/security/Synology_SA_17_68_Calendar • CWE-284: Improper Access Control •

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 0

Cross-site request forgery (CSRF) vulnerability in the Calendar plugin before 1.3.3 for WordPress allows remote attackers to hijack the authentication of users for requests that add a calendar entry via unspecified vectors. Vulnerabilidad de CSRF en el plugin Calendar anterior a 1.3.3 para WordPress permite a atacantes remotos secuestrar la autenticación de usuarios para solicitudes que añaden una entrada de calendario a través de vectores no especificados. • http://secunia.com/advisories/52841 http://wordpress.org/plugins/calendar/changelog http://www.securityfocus.com/bid/59661 https://exchange.xforce.ibmcloud.com/vulnerabilities/84032 • CWE-352: Cross-Site Request Forgery (CSRF) •