Calibre Web
by Janeczku
Source repositories
CVEs (25)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0406 | Med | 0.00 | 4.3 | 0.01 | Apr 3, 2022 | Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16. | ||
| CVE-2022-0405 | Med | 0.00 | 4.3 | 0.01 | Apr 3, 2022 | Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16. | ||
| CVE-2021-25965 | Hig | 0.00 | 8.8 | 0.01 | Nov 16, 2021 | In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the… | ||
| CVE-2021-25964 | Med | 0.00 | 5.4 | 0.01 | Oct 4, 2021 | In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered. | ||
| CVE-2020-12627 | Cri | 0.00 | 9.8 | 0.01 | May 4, 2020 | Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key. |
- risk 0.00cvss 4.3epss 0.01
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
- risk 0.00cvss 4.3epss 0.01
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.
- risk 0.00cvss 8.8epss 0.01
In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the…
- risk 0.00cvss 5.4epss 0.01
In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered.
- risk 0.00cvss 9.8epss 0.01
Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.
Page 2 of 2