github craigk5n/webcalendar v1.9.25
WebCalendar v1.9.25

3 hours ago

WebCalendar v1.9.25.

This is a security release. It fixes an unauthenticated file inclusion in
js_cacher.php and a reflected cross-site scripting issue in the category
picker and availability view. All installations should upgrade. It also
makes the MCP server work in release zips and Docker images for the first
time. There are no database changes.

Security

Unauthenticated file inclusion in js_cacher.php. The inc parameter
was checked only for a leading js/, and .. was not filtered, so a request
such as js_cacher.php?inc=js/../../../../../etc/passwd returned any file the
web server could read. PHP files elsewhere on the server could be executed in
WebCalendar's context in the same way. No login was required. Only files
directly inside includes/js/ can be included now. Reported by
dutchypoo.

Reflected XSS in catsel.php and availability.php. Request values
(the form name, and the availability view's date) were written unescaped into
a <script src> attribute and into the JavaScript served for it, so a crafted
link could run script in a logged-in user's session. The values are now
URL-encoded in the attribute and restricted to integers or plain identifiers
in the script.

Fixed

  • The MCP server was unavailable in every release zip and Docker image,
    because neither shipped the MCP SDK.
    The SDK and its runtime dependencies
    now ship in includes/classes/mcp-sdk/ (#796, #797).
  • The documented Docker quick start failed on a fresh clone.
    docker/docker-compose-prod.yml now builds the image instead of trying to
    pull one that does not exist (#793).
  • includes/zone.tab shipped with CRLF line endings, so the Security
    Audit reported it as modified on installations where nothing had been
    modified (#788).
  • docs/mcp-server.md described token setup that no longer exists, and three
    documents still gave PHP 8.0 as the minimum, rather than 8.2 (#793).

Changed

  • The Security Audit now says when a file differs only in line endings,
    and says that no action is needed, instead of advising a restore from the
    release zip.

See CHANGELOG.md for full details.

Verifying this release

WebCalendar releases ship a signed manifest. See docs/release-signing.md for
verification instructions.

Don't miss a new webcalendar release

NewReleases is sending notifications on new releases.