-
CVSS Score
-The vulnerability involves XSS via the legal_settings parameter, which implies two key points: 1) Input handling without sanitization when saving settings, and 2) Unsafe output rendering when displaying settings. While exact code isn't available, typical MVC patterns suggest:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| alextselegidis/easyappointments | composer | <= 1.5.0 |