{"containers":{"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users, making it possible for JavaScript stored in those fields to be executed by another (possibly privileged) user. Affected database fields include Username, Display Name, and Email."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2019-12-16T10:06:12.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"https://www.davical.org/"},{"tags":["x_refsource_MISC"],"url":"https://gitlab.com/davical-project/davical/blob/master/ChangeLog"},{"tags":["x_refsource_MISC"],"url":"https://hackdefense.com/publications/cve-2019-18347-davical-caldav-server-vulnerability/"},{"name":"20191210 CVE-2019-18347 Persistent Cross-Site Scripting (XSS) vulnerability in DAViCal CalDAV Server","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2019/Dec/17"},{"name":"20191210 CVE-2019-18345 Reflected Cross-Site Scripting (XSS) vulnerability in DAViCal CalDAV Server","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2019/Dec/19"},{"name":"20191210 CVE-2019-18346 Cross-Site Request Forgery (CSRF) vulnerability in DAViCal CalDAV Server","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2019/Dec/18"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/155628/DAViCal-CalDAV-Server-1.1.8-Persistent-Cross-Site-Scripting.html"},{"name":"[debian-lts-announce] 20191214 [SECURITY] [DLA 2034-1] davical security update","tags":["mailing-list","x_refsource_MLIST"],"url":"https://lists.debian.org/debian-lts-announce/2019/12/msg00016.html"},{"name":"DSA-4582","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"https://www.debian.org/security/2019/dsa-4582"},{"name":"20191216 [SECURITY] [DSA 4582-1] davical security update","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"https://seclists.org/bugtraq/2019/Dec/30"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-18347","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users, making it possible for JavaScript stored in those fields to be executed by another (possibly privileged) user. Affected database fields include Username, Display Name, and Email."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://www.davical.org/","refsource":"MISC","url":"https://www.davical.org/"},{"name":"https://gitlab.com/davical-project/davical/blob/master/ChangeLog","refsource":"MISC","url":"https://gitlab.com/davical-project/davical/blob/master/ChangeLog"},{"name":"https://hackdefense.com/publications/cve-2019-18347-davical-caldav-server-vulnerability/","refsource":"MISC","url":"https://hackdefense.com/publications/cve-2019-18347-davical-caldav-server-vulnerability/"},{"name":"20191210 CVE-2019-18347 Persistent Cross-Site Scripting (XSS) vulnerability in DAViCal CalDAV Server","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2019/Dec/17"},{"name":"20191210 CVE-2019-18345 Reflected Cross-Site Scripting (XSS) vulnerability in DAViCal CalDAV Server","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2019/Dec/19"},{"name":"20191210 CVE-2019-18346 Cross-Site Request Forgery (CSRF) vulnerability in DAViCal CalDAV Server","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2019/Dec/18"},{"name":"http://packetstormsecurity.com/files/155628/DAViCal-CalDAV-Server-1.1.8-Persistent-Cross-Site-Scripting.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/155628/DAViCal-CalDAV-Server-1.1.8-Persistent-Cross-Site-Scripting.html"},{"name":"[debian-lts-announce] 20191214 [SECURITY] [DLA 2034-1] davical security update","refsource":"MLIST","url":"https://lists.debian.org/debian-lts-announce/2019/12/msg00016.html"},{"name":"DSA-4582","refsource":"DEBIAN","url":"https://www.debian.org/security/2019/dsa-4582"},{"name":"20191216 [SECURITY] [DSA 4582-1] davical security update","refsource":"BUGTRAQ","url":"https://seclists.org/bugtraq/2019/Dec/30"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T01:54:13.439Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.davical.org/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://gitlab.com/davical-project/davical/blob/master/ChangeLog"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://hackdefense.com/publications/cve-2019-18347-davical-caldav-server-vulnerability/"},{"name":"20191210 CVE-2019-18347 Persistent Cross-Site Scripting (XSS) vulnerability in DAViCal CalDAV Server","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2019/Dec/17"},{"name":"20191210 CVE-2019-18345 Reflected Cross-Site Scripting (XSS) vulnerability in DAViCal CalDAV Server","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2019/Dec/19"},{"name":"20191210 CVE-2019-18346 Cross-Site Request Forgery (CSRF) vulnerability in DAViCal CalDAV Server","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2019/Dec/18"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/155628/DAViCal-CalDAV-Server-1.1.8-Persistent-Cross-Site-Scripting.html"},{"name":"[debian-lts-announce] 20191214 [SECURITY] [DLA 2034-1] davical security update","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://lists.debian.org/debian-lts-announce/2019/12/msg00016.html"},{"name":"DSA-4582","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"https://www.debian.org/security/2019/dsa-4582"},{"name":"20191216 [SECURITY] [DSA 4582-1] davical security update","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"https://seclists.org/bugtraq/2019/Dec/30"}]}]},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2019-18347","datePublished":"2019-12-04T17:22:37.000Z","dateReserved":"2019-10-23T00:00:00.000Z","dateUpdated":"2024-08-05T01:54:13.439Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}