CVE-2021-45914 Information

Description

In LuxSoft LuxCal Web Calendar before 5.2.0 an unauthenticated attacker can manipulate a POST request. This allows the attacker’s session to be authenticated as any registered LuxCal user including the site administrator.

Reference

https://h1pmnh.github.io/post/cve-luxcal-2021/ https://github.com/h1pmnh https://twitter.com/h1pmnh https://www.luxsoft.eu/index.php?pge=dload

Share on: