CVE-2021-42078

CVE-2021-42078

PHP Event Calendar through 2021-11-04 allows persistent cross-site scripting (XSS), as demonstrated by the /server/ajax/events_manager.php title parameter. This can be exploited by an adversary in multiple ways, e.g., to perform actions on the page in the context of other users, or to deface the site.

Source: CVE-2021-42078

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다