VDB
CVE-2019-18347
CVE-2019-18347
PUBLISHED
A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users, making it possible for JavaScript stored in those fields to be executed by another (possibly privileged) user. Affected database fields include Username, Display Name, and Email.
EPSS 0.75% · 73.5th percentile
Risk Scores
EPSS Score
0.75%
73.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | davical | 1.1.4-1ubuntu1.1, 0, 1.1.3.1-1 |
| Ubuntu:18.04:LTS | davical | 1.1.6-1, 1.1.7-1, 0 |
Exploit Intelligence
- https://hackdefense.com/publications/cve-2019-18347-davical-caldav-server-vulnerability/ (nist-nvd)
- https://www.davical.org/ (circl)
- https://gitlab.com/davical-project/davical/blob/master/ChangeLog (circl)
- 20191210 CVE-2019-18347 Persistent Cross-Site Scripting (XSS) vulnerability in DAViCal CalDAV Server (circl)
- 20191210 CVE-2019-18345 Reflected Cross-Site Scripting (XSS) vulnerability in DAViCal CalDAV Server (circl)
- 20191210 CVE-2019-18346 Cross-Site Request Forgery (CSRF) vulnerability in DAViCal CalDAV Server (circl)
- http://packetstormsecurity.com/files/155628/DAViCal-CalDAV-Server-1.1.8-Persistent-Cross-Site-Scripting.html (circl)
- [debian-lts-announce] 20191214 [SECURITY] [DLA 2034-1] davical security update (circl)
- DSA-4582 (circl)
- 20191216 [SECURITY] [DSA 4582-1] davical security update (circl)
Timeline
- Dec 4, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-18347 third-party-advisory
- https://hackdefense.com/publications/cve-2019-18347-davical-caldav-server-vulnerability/ third-party-advisory
- https://gitlab.com/davical-project/davical/blob/master/ChangeLog third-party-advisory
- https://www.davical.org/ third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-18347 third-party-advisory