Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown

CVE-2021-3988

Disclosure Date: November 15, 2024 (last updated November 20, 2024)
A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The vulnerability occurs when editing book properties, such as uploading a cover or a format. The affected code directly inserts user input into the DOM without proper sanitization, allowing attackers to execute arbitrary JavaScript code. This can lead to various attacks, including stealing cookies. The issue is present in the code handling the `#btn-upload-cover` change event.
Attacker Value
Unknown

CVE-2021-3987

Disclosure Date: November 15, 2024 (last updated November 20, 2024)
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the user has the necessary permissions to create a public shelf. This issue can lead to unauthorized actions being performed by users.
Attacker Value
Unknown

CVE-2021-3986

Disclosure Date: November 15, 2024 (last updated November 20, 2024)
A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221, where the name of the shelf is exposed in an error message when a user attempts to remove a book from a shelf they do not own. This vulnerability discloses private information and affects all versions prior to the fix.
Attacker Value
Unknown

CVE-2023-2106

Disclosure Date: April 15, 2023 (last updated November 20, 2024)
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.
Attacker Value
Unknown

CVE-2022-2525

Disclosure Date: April 15, 2023 (last updated November 20, 2024)
Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.
Attacker Value
Unknown

CVE-2022-30765

Disclosure Date: May 16, 2022 (last updated November 20, 2024)
Calibre-Web before 0.6.18 allows user table SQL Injection.
Attacker Value
Unknown

CVE-2022-0990

Disclosure Date: April 04, 2022 (last updated November 20, 2024)
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
Attacker Value
Unknown

CVE-2022-0939

Disclosure Date: April 04, 2022 (last updated November 20, 2024)
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
Attacker Value
Unknown

CVE-2022-0406

Disclosure Date: April 03, 2022 (last updated November 20, 2024)
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
Attacker Value
Unknown

CVE-2022-0405

Disclosure Date: April 03, 2022 (last updated November 20, 2024)
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.