open-web-calendar@1.44 vulnerabilities

Embed a highly customizable web calendar into your website using ICal source links

  • latest version

    1.49

  • latest non vulnerable version

  • first published

    8 months ago

  • latest version published

    2 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the open-web-calendar package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    open-web-calendar is an Embed a highly customizable web calendar into your website using ICal source links

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to missing validations in URL protocols and unsanitized error messages, leading to data theft or session hijacking.

    How to fix Cross-site Scripting (XSS)?

    Upgrade open-web-calendar to version 1.45 or higher.

    [,1.45)