Impact
SOY Calendar is vulnerable to cross‑site scripting, enabling an attacker to inject and execute arbitrary JavaScript within the web browser of any authenticated user. The flaw appears to originate from user input that is rendered in the browser without proper sanitization; this inference comes from the nature of XSS vulnerabilities but is not explicitly described in the advisory. Successful exploitation could allow an attacker to steal session cookies or perform actions on behalf of the user. The weakness corresponds to CWE‑79.
Affected Systems
The vulnerability affects the SOY Calendar product released by Tsuyoshi Saito. No specific software version list was supplied; all releases that do not contain the vendor patch should be considered vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score is <1%, indicating a very low probability of exploitation. The issue is not listed in CISA’s KEV catalog. The exploit requires an authenticated user to interact with malicious content, so the likely attack vector is via a crafted link or form submission within the application. Based on the description, it is inferred that the attacker would need a legitimate session before injection can occur. Until a vendor patch is released, the risk remains.
OpenCVE Enrichment