VDB
CVE-2019-18347
CVE-2019-18347
PUBLISHED
CVSS 5.400000095367432 MEDIUM
A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users, making it possible for JavaScript stored in those fields to be executed by another (possibly privileged) user. Affected database fields include Username, Display Name, and Email.
EPSS 1.13% · 64.3th percentile
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
1.13%
64.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | davical | 1.1.4-1ubuntu1.1, 0, 1.1.3.1-1 |
| Ubuntu:18.04:LTS | davical | 1.1.6-1, 1.1.7-1, 0 |
Timeline
- Dec 4, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-18347 third-party-advisory
- https://hackdefense.com/publications/cve-2019-18347-davical-caldav-server-vulnerability/ third-party-advisory
- https://gitlab.com/davical-project/davical/blob/master/ChangeLog third-party-advisory
- https://www.davical.org/ third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-18347 third-party-advisory