CVE-2019-18345
DAViCal CalDAV Server 1.1.8 Reflective Cross Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.
Se detectó un problema de tipo XSS reflejado en DAViCal versiones hasta 1.1.8. Se hace eco del parámetro de acción sin codificación. Si un usuario visita un enlace proporcionado por el atacante, el atacante puede visualizar todos los datos que puede observar el usuario atacado, así como realizar todas las acciones en nombre del usuario. Si el usuario es un administrador, el atacante puede, por ejemplo, agregar un nuevo usuario administrador para obtener acceso completo a la aplicación.
DAViCal CalDAV Server versions 1.1.8 and below suffer from a reflective cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-10-23 CVE Reserved
- 2019-12-10 CVE Published
- 2023-11-18 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://gitlab.com/davical-project/davical/blob/master/ChangeLog | Release Notes | |
https://lists.debian.org/debian-lts-announce/2019/12/msg00016.html | Mailing List | |
https://seclists.org/bugtraq/2019/Dec/30 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.davical.org/index.php/Main_Page | 2023-02-01 | |
https://www.davical.org | 2023-02-01 | |
https://www.debian.org/security/2019/dsa-4582 | 2023-02-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Davical Search vendor "Davical" | Davical Search vendor "Davical" for product "Davical" | <= 1.1.8 Search vendor "Davical" for product "Davical" and version " <= 1.1.8" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|