Impact
SOY Calendar contains a reflected cross‑site scripting flaw that allows an attacker to inject and execute arbitrary JavaScript in the browser of any user who logs into the application. The vulnerability can be exploited to steal session cookies, deface web pages, or perform further actions on behalf of the authenticated user. The weakness is identified by CWE‑79, indicating that input is not properly sanitized or escaped before rendering.
Affected Systems
The vendor Tsuyoshi Saito provides the SOY Calendar product. No specific version information is supplied in the CVE report; therefore every deployed instance of SOY Calendar should be considered potentially affected until a patch or fix is applied.
Risk and Exploitability
The CVSS score of 4.8 suggests a moderate impact, and the EPSS score is not available. The vulnerability is not currently listed in CISA’s KEV catalog. Attackers typically need the victim to be logged in to the application, and the compromise requires user interaction or the ability to influence form data. Based on the description, the likely attack vector is via malicious input displayed in the user interface, making the flaw exploitable when users provide or view crafted data.
OpenCVE Enrichment