SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-27330

Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php.

MEDIUM 6.1EPSS 6.20%

Does this matter?

Lower severity and a low EPSS score (6.20%). Track it; it rarely justifies an emergency change on its own.

Description

Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
6.20% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
triconsole/datepicker calendar
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.