CVE-2022-30765
Description
Calibre-Web before 0.6.18 allows user table SQL Injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Calibre-Web before 0.6.18 has a SQL injection vulnerability in the user table, enabling potential database attacks.
Vulnerability
Calibre-Web before version 0.6.18 contains a SQL injection vulnerability in the user table. The vulnerability is present in versions prior to the fix released in 0.6.18 [2][4]. The exact code path and required configuration are not detailed in the available references.
Exploitation
An attacker with network access to the Calibre-Web application could exploit this SQL injection. The necessary privileges and exact steps are not disclosed in the references, but the vulnerability is classified as user table SQL injection, suggesting potential for database manipulation [2][4].
Impact
Successful exploitation could allow an attacker to read, modify, or delete data in the user table, potentially leading to unauthorized access, privilege escalation, or disclosure of user credentials and other sensitive information [2][4].
Mitigation
Upgrade to Calibre-Web version 0.6.18 or later, which includes the security fix [4]. No workarounds have been published. Users should always run the latest version as recommended in the security policy [2].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
calibrewebPyPI | < 0.6.18 | 0.6.18 |
Affected products
2- Calibre-Web/Calibre-Webdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-8ppf-x4gr-2x7gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-30765ghsaADVISORY
- github.com/janeczku/calibre-web/blob/master/SECURITY.mdghsax_refsource_MISCWEB
- github.com/janeczku/calibre-web/releases/tag/0.6.18ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.