Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown
CVE-2021-3988
Disclosure Date: November 15, 2024 (last updated November 20, 2024)
A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The vulnerability occurs when editing book properties, such as uploading a cover or a format. The affected code directly inserts user input into the DOM without proper sanitization, allowing attackers to execute arbitrary JavaScript code. This can lead to various attacks, including stealing cookies. The issue is present in the code handling the `#btn-upload-cover` change event.
0
Attacker Value
Unknown
CVE-2021-3987
Disclosure Date: November 15, 2024 (last updated November 20, 2024)
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the user has the necessary permissions to create a public shelf. This issue can lead to unauthorized actions being performed by users.
0
Attacker Value
Unknown
CVE-2021-3986
Disclosure Date: November 15, 2024 (last updated November 20, 2024)
A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221, where the name of the shelf is exposed in an error message when a user attempts to remove a book from a shelf they do not own. This vulnerability discloses private information and affects all versions prior to the fix.
0
Attacker Value
Unknown
CVE-2023-2106
Disclosure Date: April 15, 2023 (last updated November 20, 2024)
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.
0
Attacker Value
Unknown
CVE-2022-2525
Disclosure Date: April 15, 2023 (last updated November 20, 2024)
Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.
0
Attacker Value
Unknown
CVE-2022-30765
Disclosure Date: May 16, 2022 (last updated November 20, 2024)
Calibre-Web before 0.6.18 allows user table SQL Injection.
0
Attacker Value
Unknown
CVE-2022-0990
Disclosure Date: April 04, 2022 (last updated November 20, 2024)
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
0
Attacker Value
Unknown
CVE-2022-0939
Disclosure Date: April 04, 2022 (last updated November 20, 2024)
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
0
Attacker Value
Unknown
CVE-2022-0406
Disclosure Date: April 03, 2022 (last updated November 20, 2024)
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
0
Attacker Value
Unknown
CVE-2022-0405
Disclosure Date: April 03, 2022 (last updated November 20, 2024)
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.
0