First published: Tue Feb 18 2025(Updated: )
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
LuxCal | <5.3.3M | |
LuxCal | <5.3.3L |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25223 is considered a critical severity vulnerability due to its potential for arbitrary file access.
To fix CVE-2025-25223, upgrade LuxCal Web Calendar to version 5.3.3M for MySQL or 5.3.3L for SQLite.
CVE-2025-25223 affects LuxCal Web Calendar versions prior to 5.3.3M and 5.3.3L.
CVE-2025-25223 is classified as a path traversal vulnerability.
Exploitation of CVE-2025-25223 could allow an attacker to gain access to arbitrary files on the server.