CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-25224: The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in...

5.3 CVSS

Description

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.

Classification

CVE ID: CVE-2025-25224

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

Vendor: LuxSoft

Product: The LuxCal Web Calendar

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.13% (probability of being exploited)

EPSS Percentile: 29.94% (scored less or equal to compared to others)

EPSS Date: 2025-03-19 (when was this score calculated)

References

https://www.luxsoft.eu/?download
https://www.luxsoft.eu/lcforum/viewtopic.php?pid=1984#p1984
https://jvn.jp/en/jp/JVN26024080/

Timeline