CVE-2025-25224
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
18/02/2025
Last modified:
15/09/2025
Description
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:luxsoft:luxcal_web_calendar:*:*:sqlite:*:*:*:*:* | 5.3.3l (excluding) | |
| cpe:2.3:a:luxsoft:luxcal_web_calendar:*:*:mysql:*:*:*:*:* | 5.3.3m (excluding) |
To consult the complete list of CPE names with products and versions, see this page



