CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-25223: The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in...

5.8 CVSS

Description

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.

Classification

CVE ID: CVE-2025-25223

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.8

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Affected Products

Vendor: LuxSoft

Product: The LuxCal Web Calendar

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.06% (probability of being exploited)

EPSS Percentile: 16.1% (scored less or equal to compared to others)

EPSS Date: 2025-03-19 (when was this score calculated)

References

https://www.luxsoft.eu/?download
https://www.luxsoft.eu/lcforum/viewtopic.php?pid=1984#p1984
https://jvn.jp/en/jp/JVN26024080/

Timeline