CVE-2022-4522
Status: ModifiedMedium (6.1)—
A vulnerability classified as problematic was found in CalendarXP up to 10.0.1. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 10.0.2 is able to address this issue. The name of the patch is e3715b2228ddefe00113296069969f9e184836da. It is recommended to upgrade the affected component. VDB-215902 is the identifier assigned to this vulnerability.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Base score: 6.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.56%
- Percentile among all scored CVEs: 45
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-707
References
- https://github.com/victorwon/calendarxp/commit/e3715b2228ddefe00113296069969f9e184836da
- https://github.com/victorwon/calendarxp/releases/tag/10.0.2
- https://vuldb.com/?id.215902
- https://github.com/victorwon/calendarxp/commit/e3715b2228ddefe00113296069969f9e184836da
- https://github.com/victorwon/calendarxp/releases/tag/10.0.2
- https://vuldb.com/?id.215902
Raw JSON (NVD)
Show
{
"id": "CVE-2022-4522",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-4522",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-04-14T17:03:42.853322Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.5,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cna@vuldb.com",
"affectedData": [
{
"vendor": "unspecified",
"product": "CalendarXP",
"versions": [
{
"status": "affected",
"version": "10.0.0"
},
{
"status": "affected",
"version": "10.0.1"
}
]
}
]
}
],
"published": "2022-12-15T21:15:12.853",
"references": [
{
"url": "https://github.com/victorwon/calendarxp/commit/e3715b2228ddefe00113296069969f9e184836da",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cna@vuldb.com"
},
{
"url": "https://github.com/victorwon/calendarxp/releases/tag/10.0.2",
"tags": [
"Third Party Advisory"
],
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.215902",
"tags": [
"Third Party Advisory"
],
"source": "cna@vuldb.com"
},
{
"url": "https://github.com/victorwon/calendarxp/commit/e3715b2228ddefe00113296069969f9e184836da",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/victorwon/calendarxp/releases/tag/10.0.2",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://vuldb.com/?id.215902",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"description": [
{
"lang": "en",
"value": "CWE-707"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability classified as problematic was found in CalendarXP up to 10.0.1. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 10.0.2 is able to address this issue. The name of the patch is e3715b2228ddefe00113296069969f9e184836da. It is recommended to upgrade the affected component. VDB-215902 is the identifier assigned to this vulnerability."
},
{
"lang": "es",
"value": "Una vulnerabilidad fue encontrada en CalendarXP hasta 10.0.1 y clasificada como problemática. Esta vulnerabilidad afecta a código desconocido. La manipulación conduce a Cross-Site Scripting. El ataque se puede iniciar de forma remota. La actualización a la versión 10.0.2 puede solucionar este problema. El nombre del parche es e3715b2228ddefe00113296069969f9e184836da. Se recomienda actualizar el componente afectado. VDB-215902 es el identificador asignado a esta vulnerabilidad."
}
],
"lastModified": "2026-06-17T05:21:06.070",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:calendarxp:calendarxp:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "979CC2AF-F128-4B4A-B192-8F08BBCBECEF",
"versionEndIncluding": "10.0.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@vuldb.com"
}