{"id":"CVE-2023-43658","summary":"Improper escaping of user input in discourse-calendar","details":"dicourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar in the first post of a topic. Improper escaping of event titles could lead to Cross-site Scripting (XSS) within the 'email preview' UI when a site has CSP disabled. Having CSP disabled is a non-default configuration, so the vast majority of sites are unaffected. This problem is resolved in the latest version of the discourse-calendar plugin. Users are advised to upgrade. Users unable to upgrade should ensure CSP is enabled on the forum.","aliases":["GHSA-3fwj-f6ww-7hr6"],"modified":"2026-04-02T09:24:57.397579Z","published":"2023-10-16T21:28:57.341Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/43xxx/CVE-2023-43658.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/43xxx/CVE-2023-43658.json"},{"type":"ADVISORY","url":"https://github.com/discourse/discourse-calendar/security/advisories/GHSA-3fwj-f6ww-7hr6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-43658"},{"type":"FIX","url":"https://github.com/discourse/discourse-calendar/commit/9788310906febb36822d6823d14f1059c39644de"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/discourse/discourse-calendar","events":[{"introduced":"0"},{"fixed":"9788310906febb36822d6823d14f1059c39644de"}]},{"type":"GIT","repo":"https://github.com/discourse/discourse-calendar","events":[{"introduced":"0"},{"fixed":"9788310906febb36822d6823d14f1059c39644de"}]}],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"2023-10-16"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-43658.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}