Loading HuntDB...

GHSA-frqr-7x7p-q8jj

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this issue only affects users with an account on the vulnerable service. Other users are unaffected.*. This vulnerability affects Firefox < 67.

Related CVEs

Key Information

GHSA ID
GHSA-frqr-7x7p-q8jj
Published
May 24, 2022 4:50 PM
Last Modified
April 4, 2024 1:20 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.