CVE Published: 20/11/2023 |
CVE Updated: 29/08/2024 |
CVE Year: 2023 Source: jpcert |
Vendor: LuxSoft |
Product: LuxCal Web Calendar Status : PUBLISHED
CVE-2023-46700 Description
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and obtain or alter information stored in the database.