First published: Tue May 24 2022(Updated: )
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LuxCal | <5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for LuxSoft LuxCal Web Calendar is CVE-2021-45914.
The severity of CVE-2021-45914 is critical with a CVSS score of 9.8.
An unauthenticated attacker can exploit CVE-2021-45914 by manipulating a POST request, which allows their session to be authenticated as any registered LuxCal user.
LuxSoft LuxCal Web Calendar versions up to and excluding 5.2.0 are affected by CVE-2021-45914.
Yes, the fix for CVE-2021-45914 is to update LuxSoft LuxCal Web Calendar to version 5.2.0 or later.