Summary
Detail | |||
---|---|---|---|
Vendor | Kieranoshea | First view | 2014-05-27 |
Product | Calendar | Last view | 2019-05-13 |
Version | Type | Application | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:a:kieranoshea:calendar:*:*:*:*:*:wordpress:*:* | 2 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
5.4 | 2019-05-13 | CVE-2018-18872 | The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin/admin.php?page=calendar add action, or the category name during category creation at the wp-admin/admin.php?page=calendar-categories URI. |
6.8 | 2014-05-27 | CVE-2013-2698 | Cross-site request forgery (CSRF) vulnerability in the Calendar plugin before 1.3.3 for WordPress allows remote attackers to hijack the authentication of users for requests that add a calendar entry via unspecified vectors. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
50% (1) | CWE-352 | Cross-Site Request Forgery (CSRF) |
50% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |