crocodilestick/Calibre-Web-Automated

crocodilestick/Calibre-Web-Automated

Releases27
Frequency3 weeks 1 day
Last Release
Stars5.71K
Calibre-Web but Automated and with tons of New Features! Fully automate and simplify your eBook set up!

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM6.4 MEDIUM

A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

6.3 MEDIUM6.5 MEDIUM

A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token of the file cps/kobo_auth.py of the component Kobo auth-token Route. The manipulation results in improper authorization. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.0.7 addresses this issue. The patch is identified as 9f50bb2c16160564c9f8777dc2ceed3eb95e4807. The affected component should be upgraded.