cleantalk
Vulnerabilities and Security Researches

Spiffy Calendar, CVE-2017-9420

CVE, Research URL

CVE-2017-9420

Application

Spiffy Calendar

Published on
Jun 06, 2017
Research Description
Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.
Affected versions
max 4.9.1.
Status
vulnerable