CVE-2023-47609: OSS-Calendar OSS Calendar
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
SQL injection vulnerability in OSS Calendar versions prior to v.2.0.3 allows a remote authenticated attacker to execute arbitrary code or obtain and/or alter the information stored in the database by sending a specially crafted request.
Affected products
- OSS-Calendar OSS Calendar: before 2.0.3 (fixed in 2.0.3)
Published 2023-11-14. Last modified 2026-06-17.