Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-02-25T15:11:58
Updated: 2024-08-03T20:48:16.143Z
Reserved: 2021-02-16T00:00:00
Link: CVE-2021-27330
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-02-25T16:15:12.260
Modified: 2024-11-21T05:57:48.180
Link: CVE-2021-27330
Redhat
No data.