CVE-2023-47175: XSS
Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the product.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-47175.
What is the severity of CVE-2023-47175?
The severity of CVE-2023-47175 is medium.
What is the affected software of CVE-2023-47175?
The affected software of CVE-2023-47175 is LuxCal Web Calendar versions prior to 5.2.4M (MySQL version) and LuxCal Web Calendar versions prior to 5.2.4L (SQLite version).
How does CVE-2023-47175 impact users?
CVE-2023-47175 allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the LuxCal Web Calendar.
Are there any references for CVE-2023-47175?
Yes, you can find more information about CVE-2023-47175 on the Luxsoft website. The references are available at the following URLs: [https://www.luxsoft.eu/](https://www.luxsoft.eu/), [https://www.luxsoft.eu/?download](https://www.luxsoft.eu/?download), [https://www.luxsoft.eu/lcforum/viewtopic.php?id=476](https://www.luxsoft.eu/lcforum/viewtopic.php?id=476).