{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-78071/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:digital_peak:dpcalendar_free:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-78071"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DPCalendar Free (\u003c= 10.11.2)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xss","cve-2026-78071"],"_cs_type":"advisory","_cs_vendors":["Digital Peak"],"content_html":"\u003cp\u003eDPCalendar Free versions 10.11.2 and earlier contain a stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-78071. The flaw resides in the handling of the location title field, which is rendered without proper output encoding in \u003ccode\u003edefault_locations.php\u003c/code\u003e. An attacker with Author-level privileges (the minimum role required to create events) can exploit a design flaw where the event publication state is not verified during the edit process. By creating a legitimate-looking event, waiting for administrator approval, and subsequently modifying the event location title with a crafted payload, an attacker can bypass content review. The injected JavaScript, typically using an \u003ccode\u003eonmouseover\u003c/code\u003e handler, executes in the browser of any user who hovers over the event's location information section. This vulnerability poses a significant risk for account takeover through session cookie theft and unauthorized actions on behalf of site visitors and administrators.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the target Joomla instance as an Author-role user.\u003c/li\u003e\n\u003cli\u003eAttacker creates a benign event with a legitimate location to establish trust and submit for publication.\u003c/li\u003e\n\u003cli\u003eAdministrator reviews and publishes the event via the DPCalendar backend.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the lack of state validation in \u003ccode\u003eEventController::allowEdit()\u003c/code\u003e to modify the published event.\u003c/li\u003e\n\u003cli\u003eAttacker replaces the location title with a malicious payload containing an \u003ccode\u003eonmouseover\u003c/code\u003e attribute: \u003ccode\u003eNew Location\u0026quot; onmouseover=\u0026quot;[javascript_payload]\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe payload is stored in the database without server-side sanitization of the double-quote character.\u003c/li\u003e\n\u003cli\u003eA victim (visitor or administrator) views the event page and moves the mouse cursor over the location section.\u003c/li\u003e\n\u003cli\u003eThe browser executes the injected JavaScript within the victim's session, enabling credential exfiltration or malicious redirects.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for persistent stored XSS on public-facing event pages. Impact includes session hijacking via \u003ccode\u003edocument.cookie\u003c/code\u003e exfiltration, which facilitates account takeover, particularly if an administrator views the manipulated event. Because the exploit survives the review process, it enables silent, long-term weaponization of high-traffic sites using DPCalendar.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade DPCalendar Free to version 10.12.0 or later immediately to patch the output encoding flaw.\u003c/li\u003e\n\u003cli\u003eReview event logs for any user accounts holding Author roles that have performed unauthorized edits to already published events.\u003c/li\u003e\n\u003cli\u003eImplement a Content Security Policy (CSP) that restricts inline JavaScript execution to mitigate the impact of stored XSS vulnerabilities.\u003c/li\u003e\n\u003cli\u003eEnable and monitor web server access logs for suspicious input containing HTML event handlers (e.g., \u003ccode\u003eonmouseover\u003c/code\u003e, \u003ccode\u003eonclick\u003c/code\u003e, \u003ccode\u003eonerror\u003c/code\u003e) in URI queries or POST body parameters related to DPCalendar.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-03T11:52:43Z","date_published":"2026-09-03T11:52:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-78071-dpcalendar-xss/","summary":"DPCalendar Free versions 10.11.2 and earlier contain a stored XSS vulnerability in the location title field, allowing an Author-role user to bypass content moderation and execute arbitrary JavaScript in the browsers of site visitors.","title":"Stored XSS in DPCalendar Free via Event Location Manipulation","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-78071-dpcalendar-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-78071","version":"https://jsonfeed.org/version/1.1"}