Impact
A SQL Injection flaw exists in LuxSoft LuxCal Web Calendar, located in the rssfeed.php and common/retrieve.php endpoints. The weakness, classified as CWE‑89, permits an attacker to inject arbitrary SQL statements into queries that the application sends to the database. Successful exploitation could allow the attacker to read confidential calendar data, alter or delete entries, or execute destructive database operations, compromising confidentiality, integrity, and possibly the availability of the stored data.
Affected Systems
The vulnerability affects LuxSoft's LuxCal Web Calendar product through version 5.3.4L. Users running this release or earlier versions should verify their installation and consider upgrading or applying vendor fixes. No other vendors or products are listed by the CNA.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate severity. EPSS indicates a low exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. Based on the description, the likely attack vector is remote over the web interface; an attacker can send crafted HTTP requests to rssfeed.php or retrieve.php containing malicious SQL payloads. Exploitation requires that the attacker can reach the application through its network presence and that the application does not properly validate or parameterize the received inputs.
OpenCVE Enrichment