VendorsLuxSoftluxcalany version
Vulnerabilities

LuxSoft Luxcal any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2021-45914
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.
Published 2022-05-24 · Modified
9.8EPSS 0.016
CVE-2021-45915
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.
Published 2022-05-24 · Modified
9.8EPSS 0.016