open-web-calendar@1.38.dev29 vulnerabilities

Embed a highly customizable web calendar into your website using ICal source links

Direct Vulnerabilities

Known vulnerabilities in the open-web-calendar package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

open-web-calendar is an Embed a highly customizable web calendar into your website using ICal source links

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via embedded ICS files when the calendar embeds ICS files without verifying their JavaScript or CSS content. An attacker could potentially manipulate an iframe to reload and spoof a trusted page, leading to credential theft.

How to fix Cross-site Scripting (XSS)?

Upgrade open-web-calendar to version 1.39 or higher.

[,1.39)