Thyme · Thyme Calendar · CVE-2007-2621
**Name of the Vulnerable Software and Affected Versions**
Thyme Calendar version 1.3
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `eid` parameter in the event view.php file.
**Recommendations**
For Thyme Calendar version 1.3, avoid using the `eid` parameter in the event view.php file until the issue is resolved. As a temporary workaround, consider restricting access to the event view.php file to minimize the risk of exploitation.