Improper escaping of user input in discourse-calendar
CVE-2023-43658
What is CVE-2023-43658?
The Discourse Calendar plugin for Discourse messaging platform is susceptible to Cross-site Scripting (XSS) due to improper escaping of event titles in the email preview interface, especially when Content Security Policy (CSP) is disabled. Although this typically affects a minority of users as CSP is not a default setting, it is crucial for site administrators to upgrade to the latest version of the plugin to mitigate potential risks. For those unable to perform an upgrade, enabling CSP on their forums is strongly advised to enhance security. Further details and patches can be accessed through the provided source links.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
discourse-calendar < 97883109
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved