vendor:
FullCalendar-BS4-PHP-MySQL-JSON
by:
Cakes
8.8
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: FullCalendar-BS4-PHP-MySQL-JSON
Affected Version From: 1.21
Affected Version To: 1.21
Patch Exists: NO
Related CWE: N/A
CPE: a:waldronmatt:fullcalendar-bs4-php-mysql-json
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: CentOS7
2019
waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 – ‘description’ Cross-Site Scripting
Cross-Site scripting vulnerability in the description field. This XSS completely breaks the web application.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.