CVE-2025-25223
CVSS 3.0 Score 5.8 of 10 (medium)
Details
Published Feb 18, 2025
CWE ID 22
Summary
CVE-2025-25223 is a newly disclosed vulnerability affecting the LuxCal Web Calendar. Versions prior to 5.3.3M (MySQL) and 5.3.3L (SQLite) contain a path traversal issue in the dloader.php file. Successful exploitation of this vulnerability allows attackers to obtain arbitrary files on the affected server. This poses a significant risk, especially for systems storing sensitive information. Users are advised to update their LuxCal installations as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share