5.8
CVSSv3

CVE-2025-25223

CVSSv4: NA | CVSSv3: 5.8 | CVSSv2: NA | VMScore: 680 | EPSS: 0.00019 | KEV: Not Included
Published: 18/02/2025 Updated: 18/02/2025

Vulnerability Summary

Path Traversal Vulnerability in LuxCal Web Calendar Versions Prior to 5.3.3

LuxCal Web Calendar versions prior to 5.3.3M (MySQL) and 5.3.3L (SQLite) have a path traversal vulnerability in the dloader.php component. This vulnerability could allow an attacker to access unauthorized files on the server by manipulating file path inputs.

Vulnerable Product Search on Vulmon Subscribe to Product

luxsoft the luxcal web calendar