PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.
https://www.exploit-db.com/exploits/6526
https://exchange.xforce.ibmcloud.com/vulnerabilities/45338
https://euvd.enisa.europa.eu/vulnerability/EUVD-2008-5810