Beveiligingsadvies

CVE-2025-25224

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-02-18 00:12:21
Laatst bijgewerkt 2025-02-18 19:29:03
Toegewezen door jpcert
CVSS-score 5.3
Status PUBLISHED

Beschrijving

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.