VYPR

PHP Event Calendar

by Kaysongroup

CVEs (1)

  • CVE-2021-42077CriNov 8, 2021
    risk 0.64cvss 9.8epss 0.02

    PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database…