Cross-site scripting (XSS) vulnerability in Codewalkers ltwCalendar (aka PHP Event Calendar) before 4.2.1 allows remote attackers to inject arbitrary HTML or web script via unknown vectors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ltwcalendar | Codewalkers | 4.1.3 (including) | 4.1.3 (including) |
| Ltwcalendar | Codewalkers | 4.2 (including) | 4.2 (including) |