CVE-2022-31059

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-31059
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-31059.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-31059
Aliases
  • GHSA-c783-x9vm-xxp5
Published
2022-06-14T19:55:10Z
Modified
2025-12-04T10:23:09.306958Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Discourse Calendar Event names susceptible to Cross-site Scripting
Details

Discourse Calendar is a calendar plugin for Discourse, an open-source messaging app. Prior to version 1.0.1, parsing and rendering of Event names can be susceptible to cross-site scripting (XSS) attacks. This vulnerability only affects sites which have modified or disabled Discourse’s default Content Security Policy. This issue is patched in version 1.0.1 of the Discourse Calendar plugin. As a workaround, ensure that the Content Security Policy is enabled, and has not been modified in a way which would make it more vulnerable to XSS attacks.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31059.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/discourse/discourse-calendar

Affected ranges

Type
GIT
Repo
https://github.com/discourse/discourse-calendar
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-31059.json"