linuxserver/calibre-web
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| = *, < 0.6.20 | 9.8 CRITICAL | — | ||
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. | ||||
| = *, < 0.6.20 | 9.8 CRITICAL | — | ||
Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. | ||||
| = 0.6.18, < 0.6.18 | 9.8 CRITICAL | 7.5 HIGH | ||
Calibre-Web before 0.6.18 allows user table SQL Injection. | ||||
| = *, < 0.6.18 | 9.1 CRITICAL | 6.4 MEDIUM | ||
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | ||||
| = *, < 0.6.18 | 9.9 CRITICAL | 7.5 HIGH | ||
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | ||||
| = *, < 0.6.16 | 4.3 MEDIUM | 4 MEDIUM | ||
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16. | ||||
| = *, < 0.6.16 | 4.3 MEDIUM | 4 MEDIUM | ||
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16. | ||||
| = *, < 0.6.17 | 9.8 CRITICAL | 7.5 HIGH | ||
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. | ||||
| = *, < 0.6.17 | 9.9 CRITICAL | 7.5 HIGH | ||
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. | ||||
| = *, < 0.6.16 | 9.8 CRITICAL | 7.5 HIGH | ||
Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16. | ||||
| = *, < 0.6.16 | 6.5 MEDIUM | 4 MEDIUM | ||
Improper Access Control in Pypi calibreweb prior to 0.6.16. | ||||
| = *, < 0.6.16 | 6.1 MEDIUM | 4.3 MEDIUM | ||
Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16. | ||||
| = *, < 0.6.15 | 8.8 HIGH | 6.8 MEDIUM | ||
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) | ||||
| = *, < 0.6.15 | 9.8 CRITICAL | 7.5 HIGH | ||
calibre-web is vulnerable to Business Logic Errors | ||||
| = *, < 0.6.15 | 5.4 MEDIUM | 3.5 LOW | ||
calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||||
| = *, >= 0.6.0, <= 0.6.13 | 8.8 HIGH | 6.8 MEDIUM | ||
In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the application. | ||||
| = *, >= 0.6.0, < 0.6.12 | 5.4 MEDIUM | 3.5 LOW | ||
In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered. | ||||