CVE-2025-25222: SQL Injection
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrieve.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LuxCal Web Calendarto a version that resolves this vulnerability.Fixed in 5.3.3M - Upgrade
Upgrade
LuxCal Web Calendarto a version that resolves this vulnerability.Fixed in 5.3.3L
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25222?
CVE-2025-25222 is classified as a high severity SQL injection vulnerability, potentially allowing unauthorized access to sensitive database information.
How do I fix CVE-2025-25222?
To fix CVE-2025-25222, upgrade LuxCal Web Calendar to version 5.3.3M for MySQL or 5.3.3L for SQLite.
What versions of LuxCal Web Calendar are affected by CVE-2025-25222?
CVE-2025-25222 affects LuxCal Web Calendar versions prior to 5.3.3M for MySQL and prior to 5.3.3L for SQLite.
What are the potential impacts of exploiting CVE-2025-25222?
Exploitation of CVE-2025-25222 could lead to the deletion, alteration, or retrieval of sensitive database information.
Is CVE-2025-25222 related to any specific files in LuxCal Web Calendar?
CVE-2025-25222 specifically affects the retrieve.php file within LuxCal Web Calendar.