open-web-calendar@1.38.dev29 vulnerabilities
Embed a highly customizable web calendar into your website using ICal source links
-
latest version
1.41
-
latest non vulnerable version
-
first published
4 months ago
-
latest version published
a month ago
-
licenses detected
- [0,)
Direct Vulnerabilities
Known vulnerabilities in the open-web-calendar package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
open-web-calendar is an Embed a highly customizable web calendar into your website using ICal source links Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via embedded ICS files when the calendar embeds ICS files without verifying their JavaScript or CSS content. An attacker could potentially manipulate an iframe to reload and spoof a trusted page, leading to credential theft. How to fix Cross-site Scripting (XSS)? Upgrade |
[,1.39)
|