Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-39939: LuxSoft Home

SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.

CVE
#sql#vulnerability#web#java#php#auth

Yes, you landed on the LuxSoft website.

The LuxSoft website had a facelift to give it a more
modern look ‘n’ feel and to make it more responsive.

We hope you will 🧡 it

(click this box to cancel it)

Home

LuxCal Web Calendar

LuxCal is a free user-friendly, intuitive web calendar. It can help you to organize and keep track of your events and appointments in an easy way from your phone, tablet or PC at home, in the office, on business trips or when on holiday. LuxCal has all essential functions you may expect from a modern web calendar and is targeted at home use and small businesses.

Highlights

  • intuitive, friendly user interface
  • multi-user access with user name / password protection
  • users and user groups with selectable privileges
  • optionally multiple, independent calendars
  • multi-language user interface (see section below)
  • repeating and multi-day events
  • fully tailorable to your needs, e.g. date and time formats, user interface layout, colors, etc.
  • event coloring (text and background) according to event categories
  • email and SMS reminders x days before the event is due
  • event categories and subcategories
  • event filtering on various criteria
  • full text search with wildcards
  • different views, e.g. year, month, week, day, upcoming, changes and more
  • proposing events and approving events (e.g. by manager)
  • importing and exporting of events
  • easy to administer and maintain
  • fully self contained and therefore fast (no links to external software)
  • various possibilities to embed the calendar in a page of your website
  • PHP-powered, with HTML, JavaScript and CSS
  • using an SQLIte or MySQL database (your choice)
  • released under the GNU General Public License
  • actively supported by LuxSoft and . . . . Luxcal is free!

User Interface Languages

LuxCal user interface texts are defined in separate language packs. Most LuxCal language packs have been produced by LuxCal users in the countries concerned. The following languages are currently available:

  • Bulgarian
  • Czech
  • Danish
  • German
  • Greek
  • English
  • Spanish
  • Finnish
  • French
  • Hungarian
  • Italian
  • Dutch
  • Norwegian
  • Polish
  • Portuguese
  • Romanian
  • Russian
  • Swedish
  • Slovene
  • Turkish
  • Vietnamese

Each calendar user can choose his/her own language.

Technical Details

LuxCal is written in the PHP and JavaScript scripting languages and uses an SQLite or a MySQL database (at your choice) to store its data. So LuxCal runs on a server with one of the latest versions of PHP and - for the MySQL version - MySQL.

LuxCal produces HTML5 code and has been tested with recent versions of

Responsibility / Liability

LuxSoft maintains this calendar to the best of its abilities and will try to correct reported errors and problems whenever possible. However, LuxSoft accepts no responsibility or liability whatsoever with regard to the use of the LuxCal calendar, nor the data stored by the LuxCal calendar.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907