CVE-2023-46784

HIGH

ICS Calendar <10.12.0.3 - Path Traversal

Title source: llm
STIX 2.1

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF) vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Absolute Path Traversal, : Server Side Request Forgery.This issue affects ICS Calendar: from n/a through 10.12.0.3.

Scores

CVSS v3 8.2
EPSS 0.0050
EPSS Percentile 38.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22 CWE-918
Status published
Products (1)
Room 34 Creative Services, LLC/ICS Calendar < 10.12.0.3
Published May 17, 2024
Tracked Since Feb 18, 2026