CVE-2025-14548
## The Exploit Authenticated attacker with Contributor-level access (or higher) can persist JavaScript in `event_desc` and trigger it when a calendar page is viewed. ```bash # Store the malicious event description curl -i -k \ -H "Conte...
Read article →