ZeroHour

CVE-2021-27330

PoC ×2
CVSS 3.1
6.1 medium
EPSS
6%p93
Published
()
Modified
Description

Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.

Vendors
triconsole
Products
datepicker calendar
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.