← Back to CVE List

CVE-2024-45303

Published: 2024-09-12T19:15Z
Last Modified: 2024-09-18T20:25Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rendering event names can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse’s default Content Security Policy. The issue is patched in version 0.5 of the Discourse Calendar plugin. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt