CVE-2019-18347
Summary
| CVE | CVE-2019-18347 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-04 18:15:00 UTC |
| Updated | 2019-12-14 08:15:00 UTC |
| Description | A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users, making it possible for JavaScript stored in those fields to be executed by another (possibly privileged) user. Affected database fields include Username, Display Name, and Email. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bugtraq: [SECURITY] [DSA 4582-1] davical security update | BUGTRAQ | seclists.org | |
| [SECURITY] [DLA 2034-1] davical security update | MLIST | lists.debian.org | |
| DAViCal - DAViCal Home | MISC | www.davical.org | Product |
| ChangeLog · master · DAViCal Project / DAViCal · GitLab | MISC | gitlab.com | Release Notes, Third Party Advisory |
| CVE-2019-18347 Persistent Cross-Site Scripting (XSS) vulnerability in DAViCal CalDAV Server – HackDefense | MISC | hackdefense.com | Exploit, Third Party Advisory |
| Full Disclosure: CVE-2019-18345 Reflected Cross-Site Scripting (XSS) vulnerability in DAViCal CalDAV Server | FULLDISC | seclists.org | Third Party Advisory |
| DAViCal CalDAV Server 1.1.8 Persistent Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory |
| Full Disclosure: CVE-2019-18347 Persistent Cross-Site Scripting (XSS) vulnerability in DAViCal CalDAV Server | FULLDISC | seclists.org | Third Party Advisory |
| Debian -- Security Information -- DSA-4582-1 davical | DEBIAN | www.debian.org | |
| Full Disclosure: CVE-2019-18346 Cross-Site Request Forgery (CSRF) vulnerability in DAViCal CalDAV Server | FULLDISC | seclists.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.