CVE-2025-25221: SQL Injection
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25221?
CVE-2025-25221 has a high severity due to the potential for SQL injection which can lead to unauthorized database access.
How do I fix CVE-2025-25221?
To fix CVE-2025-25221, upgrade to LuxCal Web Calendar version 5.3.3M for MySQL or 5.3.3L for SQLite.
What are the impacts of exploiting CVE-2025-25221?
Exploiting CVE-2025-25221 could result in the deletion, alteration, or retrieval of sensitive information from the database.
Which versions are affected by CVE-2025-25221?
CVE-2025-25221 affects LuxCal Web Calendar prior to version 5.3.3M for MySQL and prior to version 5.3.3L for SQLite.
Is CVE-2025-25221 being actively exploited?
There is currently no public confirmation that CVE-2025-25221 is being actively exploited, but the vulnerability poses a significant risk if not addressed.