1.49
9 months ago
18 days ago
Known vulnerabilities in the open-web-calendar package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
open-web-calendar is an Embed a highly customizable web calendar into your website using ICal source links Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to missing validations in URL protocols and unsanitized error messages, leading to data theft or session hijacking. How to fix Cross-site Scripting (XSS)? Upgrade | [,1.45) |
open-web-calendar is an Embed a highly customizable web calendar into your website using ICal source links Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via embedded ICS files when the calendar embeds ICS files without verifying their JavaScript or CSS content. An attacker could potentially manipulate an iframe to reload and spoof a trusted page, leading to credential theft. How to fix Cross-site Scripting (XSS)? Upgrade | [,1.39) |