VYPR
Medium severity4.2NVD Advisory· Published Aug 6, 2024· Updated Jun 17, 2026

CVE-2024-7009

CVE-2024-7009

Description

Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:*range: <=7.15.0
    • (no CPE)range: <=7.15.0
  • calibre/calibrellm-fuzzy2 versions
    <=7.15.0+ 1 more
    • (no CPE)range: <=7.15.0
    • (no CPE)range: 7.15.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.