CVE-2022-4455
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
13/12/2022
Last modified:
15/12/2025
Description
A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be launched remotely. The name of the patch is a2941109b42201c19733127ced763e270a357809. It is advisable to implement a patch to correct this issue.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
3.50
Severity 3.x
LOW
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:php-calendar:php-calendar:*:*:*:*:*:*:*:* | 2022-04-28 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



