VDB
CVE-2023-51504
CVE-2023-51504
PUBLISHED
CVSS 6.5 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's Embedder for Google Calendar: from n/a through 1.2.
EPSS 0.74% · 52.9th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
EPSS Score
0.74%
52.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| dandulaney | dan\'s_embedder_for_google_calendar | 0, 0 |
| Dan Dulaney | Dan's Embedder for Google Calendar | n/a, n/a |
Timeline
- Feb 5, 2024 CVE Published
- Feb 5, 2024 PoC Published
- Feb 8, 2024 EPSS Score
- Feb 29, 2024 PoC Published
- Mar 7, 2024 EPSS Score
- May 1, 2024 EPSS Score
- May 29, 2024 EPSS Score
- Jul 23, 2024 EPSS Score
- Aug 20, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 15, 2024 EPSS Score
- Nov 11, 2024 EPSS Score