Description
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-43637 | SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it. |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 07 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Luxcal
Luxcal web Calendar |
|
| CPEs | cpe:2.3:a:luxcal:web_calendar:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Luxcal
Luxcal web Calendar |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-10-04T17:53:12.775Z
Reserved: 2023-08-09T02:20:31.626Z
Link: CVE-2023-39939
Updated: 2024-08-02T18:18:10.144Z
Status : Modified
Published: 2023-08-21T09:15:10.280
Modified: 2024-11-21T08:16:04.723
Link: CVE-2023-39939
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD