Vulnerability Details CVE-2019-18346
A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary requests in the name of the user to the application. If the attacked user is an administrator, the attacker could for example add a new admin user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 77.2%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2019-18346
-
cpe:2.3:a:davical:davical:-
-
cpe:2.3:a:davical:davical:0.9.0
-
cpe:2.3:a:davical:davical:0.9.3
-
cpe:2.3:a:davical:davical:0.9.4
-
cpe:2.3:a:davical:davical:0.9.4.3
-
cpe:2.3:a:davical:davical:0.9.4.5
-
cpe:2.3:a:davical:davical:0.9.5
-
cpe:2.3:a:davical:davical:0.9.5.2
-
cpe:2.3:a:davical:davical:0.9.5.90
-
cpe:2.3:a:davical:davical:0.9.5.91
-
cpe:2.3:a:davical:davical:0.9.6
-
cpe:2.3:a:davical:davical:0.9.6.2
-
cpe:2.3:a:davical:davical:0.9.6.3
-
cpe:2.3:a:davical:davical:0.9.7
-
cpe:2.3:a:davical:davical:0.9.7.1
-
cpe:2.3:a:davical:davical:0.9.7.2
-
cpe:2.3:a:davical:davical:0.9.7.3
-
cpe:2.3:a:davical:davical:0.9.7.4
-
cpe:2.3:a:davical:davical:0.9.8
-
cpe:2.3:a:davical:davical:0.9.8.1
-
cpe:2.3:a:davical:davical:0.9.8.2
-
cpe:2.3:a:davical:davical:0.9.8.3
-
cpe:2.3:a:davical:davical:0.9.9
-
cpe:2.3:a:davical:davical:0.9.9.1
-
cpe:2.3:a:davical:davical:0.9.9.2
-
cpe:2.3:a:davical:davical:0.9.9.3
-
cpe:2.3:a:davical:davical:0.9.9.4
-
cpe:2.3:a:davical:davical:0.9.9.5
-
cpe:2.3:a:davical:davical:0.9.9.6
-
cpe:2.3:a:davical:davical:0.9.9.7
-
cpe:2.3:a:davical:davical:1.1.0
-
cpe:2.3:a:davical:davical:1.1.1
-
cpe:2.3:a:davical:davical:1.1.2
-
cpe:2.3:a:davical:davical:1.1.3
-
cpe:2.3:a:davical:davical:1.1.4
-
cpe:2.3:a:davical:davical:1.1.5
-
cpe:2.3:a:davical:davical:1.1.6
-
cpe:2.3:a:davical:davical:1.1.7
-
cpe:2.3:a:davical:davical:1.1.8