LuxCal 5.3.5M & 5.3.5L - SQL Injection Vulnerability
====================================================

September 2026

27 August 2026 JPCERT/CC Cyber Security reported an SQL injection vulnerability (ID JVN#65245156) for the LuxCal web calendar.
It was confirmed that authentication could be bypassed to access administrator pages.

This problem has been solved in the enclosed files.
LuxCal administrators can fix this problem in their LuxCal calendar in the following way:
- Take care that you are using LuxCal version 5.3.5M or 5.3.5L. See top of the administrator's Settings page.
- upload file index.php to the calendar's root folder
- upload file toolbox.php to the calendar's "common" folder

Should you have any questions, please use the Contact page on the LuxSoft website (www.luxsoft.eu?contact).

====================================================
