PT-2025-53869 · Unknown+1 · Simplecalendar+1

Doan Dinh Van

·

Published

2025-12-30

·

Updated

2025-12-31

·

CVE-2025-68979

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SimpleCalendar versions through 3.5.9
Description An authorization bypass exists due to user-controlled key vulnerability in Google Calendar Events. This allows exploitation of incorrectly configured access control security levels.
Recommendations Update SimpleCalendar to a version newer than 3.5.9.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-68979

Affected Products

Google Calendar
Simplecalendar