CVE-2023-46700
20.11.2023, 05:15
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and obtain or alter information stored in the database.
| Vendor | Product | Version |
|---|---|---|
| luxsoft | luxcal_web_calendar | 𝑥 < 5.2.4l |
| luxsoft | luxcal_web_calendar | 𝑥 < 5.2.4m |
𝑥
= Vulnerable software versions