CVE-2025-25221 HIGH

CVE-2025-25221

Vendor Luxsoft
Product The LuxCal Web Calendar
Weakness CWE-89 · SQLi
Published February 18, 2025
Last update February 18, 2025

CVSS base score

7.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.

Key dates

02Disclosure timeline

February 18, 2025 CVE published
February 18, 2025 Record updated