PoC Index

CVE-2021-27330

MEDIUM 6.1EPSS 6.2%

Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
6.20% chance of exploitation in the next 30 days, 93th percentile
Nuclei
medium · CWE-79
Published
2021-02-25
Updated
2024-08-03

Proof-of-concept exploits (2)

Nuclei templates (1)

References

Related