CVE-2023-39939: SQL Injection
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39939?
CVE-2023-39939 is a SQL injection vulnerability in LuxCal Web Calendar prior to versions 5.2.3M (MySQL version) and 5.2.3L (SQLite version).
What is the severity of CVE-2023-39939?
The severity of CVE-2023-39939 is critical with a value of 9.1.
How does CVE-2023-39939 impact LuxCal Web Calendar?
CVE-2023-39939 allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.
Which software versions are affected by CVE-2023-39939?
LuxCal Web Calendar versions prior to 5.2.3M (MySQL version) and 5.2.3L (SQLite version) are affected by CVE-2023-39939.
Where can I find more information about CVE-2023-39939?
You can find more information about CVE-2023-39939 on the official LuxCal Web Calendar website and the JVN (Japan Vulnerability Notes) website.