CVE-2022-4455

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
13/12/2022
Last modified:
15/12/2025

Description

A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be launched remotely. The name of the patch is a2941109b42201c19733127ced763e270a357809. It is advisable to implement a patch to correct this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php-calendar:php-calendar:*:*:*:*:*:*:*:* 2022-04-28 (excluding)