First published: Mon Nov 20 2023(Updated: )
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and obtain or alter information stored in the database.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Luxsoft Luxcal Web Calendar | <5.2.4l | |
Luxsoft Luxcal Web Calendar | <5.2.4m |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46700 is a SQL injection vulnerability in LuxCal Web Calendar prior to version 5.2.4M (MySQL version) and 5.2.4L (SQLite version) that allows an attacker to execute arbitrary SQL commands and obtain or alter database information.
CVE-2023-46700 has a severity rating of 9.8 (Critical).
CVE-2023-46700 affects LuxCal Web Calendar versions prior to 5.2.4M (MySQL version) and 5.2.4L (SQLite version).
An attacker can exploit CVE-2023-46700 by sending a crafted request to the LuxCal Web Calendar, allowing them to execute arbitrary SQL commands.
To fix CVE-2023-46700, users should update LuxCal Web Calendar to version 5.2.4M (MySQL version) or 5.2.4L (SQLite version), which have addressed the SQL injection vulnerability.