What the vulnerability does
01Description
Missing Authorization vulnerability in beat.k Termin-Kalender termin-kalender allows Stored XSS.This issue affects Termin-Kalender: from n/a through <= 0.99.47.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in beat.k Termin-Kalender termin-kalender allows Stored XSS.This issue affects Termin-Kalender: from n/a through <= 0.99.47.
Explanation of Vulnerability in Simple Terms
Termin-Kalender versions up to 0.99.47 lack proper authorization checks, allowing authenticated users with low privileges to perform actions they should not be permitted to do. An attacker must be logged in and trick a victim into clicking a malicious link. The vulnerability can leak sensitive data, modify content, or disrupt service availability across the affected application.
What an attacker can do
Perform unauthorized actions affecting data confidentiality, integrity, and availability after logging in.
Potential impact on your site
Authenticated users can bypass access controls to view, modify, or disrupt content beyond their intended permissions.
Conditions required to exploit
Attacker must have a low-privilege user account and the victim must click a malicious link.
Key dates
External resources
Related vulnerabilities