SQL Injection Vulnerability in TeamCal Neo by TeamCal
CVE-2025-0929
9.8CRITICAL
What is CVE-2025-0929?
A SQL injection vulnerability exists in TeamCal Neo version 3.8.2, allowing attackers to execute unauthorized SQL commands. By manipulating the 'abs' parameter in the '/teamcal/src/index.php' file, an attacker can potentially retrieve, update, or delete sensitive database information, compromising the integrity and confidentiality of the data stored within the application.
Affected Version(s)
TeamCal Neo 3.8.2