Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Unknown
CVE-2021-3988
Disclosure Date: November 15, 2024 (last updated November 20, 2024)
A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The vulnerability occurs when editing book properties, such as uploading a cover or a format. The affected code directly inserts user input into the DOM without proper sanitization, allowing attackers to execute arbitrary JavaScript code. This can lead to various attacks, including stealing cookies. The issue is present in the code handling the `#btn-upload-cover` change event.
0
Attacker Value
Unknown
CVE-2021-3987
Disclosure Date: November 15, 2024 (last updated November 20, 2024)
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the user has the necessary permissions to create a public shelf. This issue can lead to unauthorized actions being performed by users.
0
Attacker Value
Unknown
CVE-2021-3986
Disclosure Date: November 15, 2024 (last updated November 20, 2024)
A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221, where the name of the shelf is exposed in an error message when a user attempts to remove a book from a shelf they do not own. This vulnerability discloses private information and affects all versions prior to the fix.
0
Attacker Value
Unknown
CVE-2024-7009
Disclosure Date: August 06, 2024 (last updated August 20, 2024)
Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.
0
Attacker Value
Unknown
CVE-2024-7008
Disclosure Date: August 06, 2024 (last updated August 20, 2024)
Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.
0
Attacker Value
Unknown
CVE-2024-6782
Disclosure Date: August 06, 2024 (last updated August 06, 2024)
Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
0
Attacker Value
Unknown
CVE-2024-6781
Disclosure Date: August 06, 2024 (last updated August 20, 2024)
Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.
0
Attacker Value
Unknown
CVE-2023-46303
Disclosure Date: October 22, 2023 (last updated October 28, 2023)
link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root.
0
Attacker Value
Unknown
CVE-2023-2106
Disclosure Date: April 15, 2023 (last updated November 20, 2024)
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.
0
Attacker Value
Unknown
CVE-2022-2525
Disclosure Date: April 15, 2023 (last updated November 20, 2024)
Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.
0