Medium severity4.2NVD Advisory· Published Aug 6, 2024· Updated Jun 17, 2026
CVE-2024-7009
CVE-2024-7009
Description
Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:*range: <=7.15.0
- (no CPE)range: <=7.15.0
Patches
Vulnerability mechanics
References
2- github.com/kovidgoyal/calibre/commit/d56574285e8859d3d715eb7829784ee74337b7d7nvdPatch
- starlabs.sg/advisories/24/24-7009/nvdExploitMitigationThird Party Advisory
News mentions
0No linked articles in our index yet.