← back
CVE-2025-0929criticalCWE-89

SQL injection vulnerability in TeamCal Neo

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 0.8%
exploitation probability
0.8%top 44% of all CVEs
observed exploitation
nono source reports it
SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete all database information by injecting a malicious SQL statement via the ‘abs’ parameter in ‘/teamcal/src/index.php’.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Lewe · TeamCal Neo