216.73.217.22

CVE-2025-66489

· Published 03/12/2025 20:16 · Modified 04/12/2025 17:15

Labels: CVE-2025-66489 2025-12-03CVE-2025-66489CWE-303[email protected]

Essential information

Published
03/12/2025 20:16
Modified
04/12/2025 17:15
Author
Creator
CVSS
9.9 CRITICAL (v3) 9.9 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in the authentication flow. This vulnerability is fixed in 5.9.8.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References