PT-2025-4100 · Unknown · Teamcal Neo

Br4V3N

+1

·

Published

2025-01-31

·

Updated

2025-02-03

·

CVE-2025-0929

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TeamCal Neo version 3.8.2
Description The issue is a SQL injection vulnerability that could allow an attacker to retrieve, update, and delete all database information by injecting a malicious SQL statement via the abs parameter in the /teamcal/src/index.php API endpoint.
Recommendations For TeamCal Neo version 3.8.2, consider disabling the abs parameter in the /teamcal/src/index.php API endpoint until a patch is available. Restrict access to the /teamcal/src/index.php endpoint to minimize the risk of exploitation. Avoid using the abs parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-0929

Affected Products

Teamcal Neo