VYPR
Medium severity5.3NVD Advisory· Published Feb 18, 2025· Updated Jun 17, 2026

CVE-2025-25223

CVE-2025-25223

Description

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:luxsoft:luxcal_web_calendar:*:*:mysql:*:*:*:*:*+ 1 more
    • cpe:2.3:a:luxsoft:luxcal_web_calendar:*:*:mysql:*:*:*:*:*range: <5.3.3m
    • cpe:2.3:a:luxsoft:luxcal_web_calendar:*:*:sqlite:*:*:*:*:*range: <5.3.3l
  • Range: <5.3.3M (MySQL), <5.3.3L (SQLite)
  • Luxsoft/The Luxcal Web Calendarllm-fuzzy2 versions
    <5.3.3M (MySQL), <5.3.3L (SQLite)+ 1 more
    • (no CPE)range: <5.3.3M (MySQL), <5.3.3L (SQLite)
    • (no CPE)range: prior to 5.3.3L (SQLite version)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.