Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the product.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.luxsoft.eu/ | product |
https://www.luxsoft.eu/?download | release notes |
https://www.luxsoft.eu/lcforum/viewtopic.php?id=476 | issue tracking |
https://jvn.jp/en/jp/JVN15005948/ | third party advisory |