CVE Published: 21/08/2023 |
CVE Updated: 04/10/2024 |
CVE Year: 2023 Source: jpcert |
Vendor: LuxSoft |
Product: LuxCal Web Calendar Status : PUBLISHED
CVE-2023-39939 Description
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.