VYPR
Critical severity9.3NVD Advisory· Published Dec 12, 2019· Updated Jun 17, 2026

CVE-2019-18345

CVE-2019-18345

Description

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • DAViCal/DAViCal2 versions
    cpe:2.3:a:davical:davical:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:davical:davical:*:*:*:*:*:*:*:*range: <=1.1.8
    • (no CPE)range: <=1.1.8
  • Debian/linux3 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • DAViCal/DAViCaldescription

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.