Vulnerability Description
A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. An attacker can inject malicious scripts, which are then executed in the context of other users who view the report, potentially leading to the theft of user accounts and cookies.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| K5N | Webcalendar | 1.3.0 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/6dd501f6-6047-4ddb-8b14-f0fc53cdc28eExploitThird Party Advisory
FAQ
What is CVE-2024-1097?
CVE-2024-1097 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. An attacker can i...
How severe is CVE-2024-1097?
CVE-2024-1097 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-1097?
Check the references section above for vendor advisories and patch information. Affected products include: K5N Webcalendar.