CVE-2019-18346: CSRF
A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary requests in the name of the user to the application. If the attacked user is an administrator, the attacker could for example add a new admin user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18346?
CVE-2019-18346 is classified as a moderate severity vulnerability due to its potential impact when exploited.
How do I fix CVE-2019-18346?
To fix CVE-2019-18346, update DAViCal to versions 1.1.10 or 1.1.12 or later, as these include a patch for this vulnerability.
Who is affected by CVE-2019-18346?
CVE-2019-18346 affects all authenticated users of DAViCal versions up to 1.1.8, especially those with administrative privileges.
What type of vulnerability is CVE-2019-18346?
CVE-2019-18346 is a Cross-Site Request Forgery (CSRF) vulnerability that can allow attackers to perform actions on behalf of a logged-in user.
Can CVE-2019-18346 lead to account takeover?
Yes, CVE-2019-18346 can lead to account takeover if an attacker exploits the vulnerability to gain administrative access.