Executive brief
SOY Calendar is a web-based calendar application. A cross-site scripting (XSS) vulnerability allows an attacker to inject malicious scripts that execute in the browser of users logging into the product, potentially stealing session credentials or performing unauthorized actions on behalf of the user.
Technical details
This is a cross-site scripting (CWE-79) vulnerability in SOY Calendar that requires an authenticated user to interact with attacker-controlled input during login. The vulnerability allows injection of arbitrary JavaScript that executes in the victim's browser with the privileges of the logged-in user. According to the advisory, the impact is limited to the client-side (cookie/session access and UI manipulation) without server-side compromise. A security patch has been released: SOY Calendar version 2.5.0 addresses this vulnerability and should be deployed immediately.
Affected products
- Tsuyoshi Saito SOY Calendar 2.4.0 and earlier
Timeline
- 2026-08-28: disclosed: Vulnerability published in JVN advisory JVN#04485476
- 2026-08-31: patched: Security update released with SOY Calendar version 2.5.0