Improper Input Neutralization in Calendar Event Feature of Product by Vendor
CVE-2023-27294

5.4MEDIUM

Key Information:

Vendor

Opencats

Status
Vendor
CVE Published:
28 February 2023

What is CVE-2023-27294?

This vulnerability arises from improper neutralization of input during the web page generation process, which allows authenticated attackers with restricted account access to submit malicious JavaScript as part of calendar event descriptions. When other users browse to these events, the injected JavaScript can execute in their browsers. Such exploitation can lead to serious risks, including the theft of session tokens from users with higher permissions and unauthorized actions taken on users' behalf, potentially compromising user accounts and sensitive data.

Affected Version(s)

OpenCATS 0.9.6

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.