Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rendering event names can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse’s default Content Security Policy. The issue is patched in version 0.5 of the Discourse Calendar plugin.
History

Wed, 18 Sep 2024 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Discourse
Discourse calendar
CPEs cpe:2.3:a:discourse:calendar:*:*:*:*:*:*:*:*
Vendors & Products Discourse
Discourse calendar

Thu, 12 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
Description Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rendering event names can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse’s default Content Security Policy. The issue is patched in version 0.5 of the Discourse Calendar plugin.
Title Discourse Calendar plugin event names susceptible to XSS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-09-12T18:11:46.513Z

Updated: 2024-09-12T19:55:25.980Z

Reserved: 2024-08-26T18:25:35.443Z

Link: CVE-2024-45303

cve-icon Vulnrichment

Updated: 2024-09-12T19:54:36.952Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-12T19:15:03.793

Modified: 2024-09-18T20:25:05.807

Link: CVE-2024-45303

cve-icon Redhat

No data.