CVE-2025-25223

CVSS 3.0 Score 5.8 of 10 (medium)

Details

Published Feb 18, 2025
CWE ID 22

Summary

CVE-2025-25223 is a newly disclosed vulnerability affecting the LuxCal Web Calendar. Versions prior to 5.3.3M (MySQL) and 5.3.3L (SQLite) contain a path traversal issue in the dloader.php file. Successful exploitation of this vulnerability allows attackers to obtain arbitrary files on the affected server. This poses a significant risk, especially for systems storing sensitive information. Users are advised to update their LuxCal installations as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share