-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| concrete5/concrete5 | composer | >= 9.0.0, < 9.3.4 | 9.3.4 |
| concrete5/concrete5 | composer | < 8.5.19 | 8.5.19 |
The analysis of the provided patches and descriptions indicates that the vulnerability is related to the output of calendar event names. The vulnerable function is related to the viewVersion method in the Event Dialog class, specifically the output of the event name.