{ "id": "CVE-2023-47175", "sourceIdentifier": "vultures@jpcert.or.jp", "published": "2023-11-20T05:15:08.953", "lastModified": "2023-11-20T15:04:56.147", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the product." }, { "lang": "es", "value": "Vulnerabilidad de Cross-site scripting en LuxCal Web Calendar anterior a 5.2.4M (versi\u00f3n MySQL) y LuxCal Web Calendar anterior a 5.2.4L (versi\u00f3n SQLite) permite a un atacante remoto no autenticado ejecutar un script arbitrario en el navegador web del usuario que est\u00e1 acceder al producto." } ], "metrics": {}, "references": [ { "url": "https://jvn.jp/en/jp/JVN15005948/", "source": "vultures@jpcert.or.jp" }, { "url": "https://www.luxsoft.eu/", "source": "vultures@jpcert.or.jp" }, { "url": "https://www.luxsoft.eu/?download", "source": "vultures@jpcert.or.jp" }, { "url": "https://www.luxsoft.eu/lcforum/viewtopic.php?id=476", "source": "vultures@jpcert.or.jp" } ] }