Security Advisory

CVE-2021-45914

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-05-24 14:32:59
Last updated 2024-08-04 04:54:30
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.