Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2025-25224

Disclosure Date: February 18, 2025 (last updated February 18, 2025)
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.
0
Attacker Value
Unknown

CVE-2025-25223

Disclosure Date: February 18, 2025 (last updated February 18, 2025)
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.
0
Attacker Value
Unknown

CVE-2025-25222

Disclosure Date: February 18, 2025 (last updated February 18, 2025)
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrieve.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.
0
Attacker Value
Unknown

CVE-2025-25221

Disclosure Date: February 18, 2025 (last updated February 18, 2025)
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.
0
Attacker Value
Unknown

CVE-2023-47175

Disclosure Date: November 20, 2023 (last updated February 25, 2025)
Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the product.
Attacker Value
Unknown

CVE-2023-46700

Disclosure Date: November 20, 2023 (last updated February 25, 2025)
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and obtain or alter information stored in the database.
Attacker Value
Unknown

CVE-2023-39939

Disclosure Date: August 21, 2023 (last updated February 25, 2025)
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.
Attacker Value
Unknown

CVE-2023-39543

Disclosure Date: August 21, 2023 (last updated February 25, 2025)
Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product.
Attacker Value
Unknown

CVE-2021-45915

Disclosure Date: May 24, 2022 (last updated October 07, 2023)
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.
Attacker Value
Unknown

CVE-2021-45914

Disclosure Date: May 24, 2022 (last updated October 07, 2023)
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.