CVE-2023-47175: Luxsoft Luxcal Web Calendar
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the product.
Affected products
- Luxsoft Luxcal Web Calendar: before 5.2.4l (fixed in 5.2.4l); before 5.2.4m (fixed in 5.2.4m)
Published 2023-11-20. Last modified 2026-06-17.