S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-27330 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Triconsole Datepicker Calendar affects v. before 3.77.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-27330
6.1
CVSS

Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Triconsole Datepicker Calendar is a popular tool used for date selection in applications. It is commonly integrated into websites, making it easy and intuitive for users to select dates. The primary purpose of the Triconsole Datepicker Calendar is to provide an enhanced user experience by simplifying the process of selecting dates and improving the accuracy of date selection. It is widely used in various industries, including travel, hospitality, and e-commerce.

The CVE-2021-27330 vulnerability was detected in the Triconsole Datepicker Calendar version 3.77. This vulnerability allows attackers to inject malicious code into the application through cross-site scripting (XSS) in calendar_form.php. Attackers can then read authentication cookies that are still active, potentially allowing them to perform further attacks such as reading browser history, directory listings, and file contents.

When exploited, this vulnerability can lead to serious consequences. Attackers can gain unauthorized access to sensitive information, including personally identifiable information (PII) and financial data. This can result in identity theft, fraud and other malicious actions. Additionally, attackers can use this information to gain access to further systems and applications, increasing the risk and potential damage of the attack.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. By utilizing advanced security scanning technology, s4e.io delivers real-time, actionable intelligence on potential threats to digital assets. This includes regular updates on vulnerabilities such as the CVE-2021-27330, ensuring that users are always up-to-date on the latest security threats. With s4e.io, users can rest assured that their digital assets are protected and secure, minimizing the risk of potential attacks.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against the CVE-2021-27330 vulnerability. These include:

  • Updating to the latest version of the Triconsole Datepicker Calendar.
  • Implementing input validation to prevent XSS attacks.
  • Monitoring and analyzing network traffic for suspicious activity.
  • Enabling Web Application Firewall (WAF) to block XSS attacks.
  • Implementing multi-factor authentication (MFA) to improve login security.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-27330 scanner - Cross-Site Scripting (XSS) vulnerability in Triconsole Datepicker Calendar | S4E