CVE-2024-27993
CVE-2024-27993: A Cross-Site Scripting (XSS) vulnerability exists in the Typps Calendarista Basic Edition, affecting versions up to 3.0.2. This vulnerability allows for the improper neutralization of input during web page generation, potentially enabling attackers to inject malicious scripts. The attack is possible due to the improper handling of user-supplied input in the Calendarista Basic Edition. While the CVSS score is 0, SOCRadar's SVRS of 30 indicates a low level of active risk. Successful exploitation could lead to session hijacking, defacement, or the redirection of users to malicious websites. Although not immediately critical, patching is recommended to mitigate potential risks, especially since it has been tagged as "In The Wild." Organizations using Calendarista Basic Edition should update to a patched version as soon as possible.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.