Intel

AIKIDO-2024-10132

add-to-calendar-button is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 21, 2024

50

Medium Risk

This Affects:

JSadd-to-calendar-button
1.0.1 - 2.6.17
Fixed in 2.6.18
Are you affected? Scan for Free

TL;DR

Affected versions of the add-to-calendar-button package are vulnerable to prototype pollution, which may lead to Cross-site Scripting (XSS).

Who does this affect?

You are affected if you use a vulnerable version of add-to-calendar-button.

Background info

add-to-calendar-button is vulnerable to Prototype Pollution in versions 1.0.1 - 2.6.17.

How to fix this

Upgrade add-to-calendar-button to a patch version.