PT-2023-30165 · Unknown · Luxcal Web Calendar

Yuji Tounai

·

Publicado

2023-11-20

·

Atualizado

2023-11-25

·

CVE-2023-46700

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LuxCal Web Calendar versions prior to 5.2.4M (MySQL version) LuxCal Web Calendar versions prior to 5.2.4L (SQLite version)
Description A SQL injection issue allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, potentially obtaining or altering information stored in the database.
Recommendations For versions prior to 5.2.4M (MySQL version), update to version 5.2.4M or later. For versions prior to 5.2.4L (SQLite version), update to version 5.2.4L or later.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-46700

Produtos afetados

Luxcal Web Calendar