Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary requests in the name of the user to the application. If the attacked user is an administrator, the attacker could for example add a new admin user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DAViCal 跨站请求伪造漏洞
Vulnerability Description
DAViCal是一款日历共享服务器,是CalDAV协议的实现。 DAViCal 1.1.8及之前版本中存在跨站请求伪造漏洞。远程攻击者可通过诱使用户访问恶意网站利用该漏洞修改e?mail地址和密码,完全控制账户,并创建新的管理员账户。
CVSS Information
N/A
Vulnerability Type
N/A