CVE-2007-3515 is a critical SQL injection vulnerability identified in SweetPHP TotalCalendar versions 2.402 and earlier, specifically affecting the view_event.php script through the id parameter. With a maximum CVSS score of 10.0, this flaw allows unauthenticated remote attackers to execute arbitrary SQL commands with low complexity, posing a severe risk to database confidentiality, integrity, and availability. Although proof-of-concept code is archived on ExploitDB, the vulnerability is not listed in the CISA KEV catalog and shows no current signs of active exploitation or significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.402CPE matchmatch criteria | cpe:2.3:a:sweetphp:totalcalendar:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.