PT-2025-43256 · Webjunk · Calendar Plus
Published
2025-10-22
·
Updated
2025-11-18
·
CVE-2025-53350
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
webjunk Calendar Plus versions through 1.2.4
Description
The software contains a flaw due to improper handling of user-supplied data when creating web pages, leading to a potential Reflected Cross-site Scripting (XSS) condition. This allows an attacker to inject malicious scripts into web pages viewed by other users. The vulnerability exists because the application does not adequately sanitize or encode user input before including it in the generated HTML output. This can allow an attacker to execute arbitrary JavaScript code in the context of a victim's browser. The vulnerable component is susceptible to attacks where a crafted URL containing malicious code is sent to a user. When the user clicks on the link, the malicious script is executed.
Recommendations
Update webjunk Calendar Plus to a version later than 1.2.4.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Calendar Plus