CVE-2022-4522
Summary
| CVE | CVE-2022-4522 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-15 21:15:00 UTC |
| Updated | 2023-11-07 03:58:00 UTC |
| Description | A vulnerability classified as problematic was found in CalendarXP up to 10.0.1. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 10.0.2 is able to address this issue. The name of the patch is e3715b2228ddefe00113296069969f9e184836da. It is recommended to upgrade the affected component. VDB-215902 is the identifier assigned to this vulnerability. |
Risk And Classification
Problem Types: CWE-707
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Calendarxp | Calendarxp | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release v10.0.2 · victorwon/calendarxp · GitHub | N/A | github.com | |
| CVE-2022-4522 | CalendarXP cross site scripting | N/A | vuldb.com | |
| fixed XSS vulnerability · victorwon/calendarxp@e3715b2 · GitHub | N/A | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.