login.php in ACal Calendar Project 2.2.5 allows remote attackers to bypass authentication by setting the ACalAuthenticate cookie variable to "inside".
- http://evuln.com/vulns/25/summary.html
No PoCs found on GitHub currently.