0.6.24
3 years ago
5 months ago
Known vulnerabilities in the calibreweb package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in the How to fix Cross-site Scripting (XSS)? Upgrade | [,0.6.22) |
calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database. Affected versions of this package are vulnerable to Weak Password Requirements due to missing rate limits in the login functionality. How to fix Weak Password Requirements? Upgrade | [,0.6.20) |
calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database. Affected versions of this package are vulnerable to Brute Force due to missing rate limiting in login form. How to fix Brute Force? Upgrade | [,0.6.20) |
calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database. Affected versions of this package are vulnerable to SQL Injection in the user table. How to fix SQL Injection? Upgrade | [,0.6.18) |
calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) due to improper fix of CVE-2022-0767 and CVE-2022-0766 which only address loopback/localhost IP addresses which can allow attacker to access internal endpoints. How to fix Server-side Request Forgery (SSRF)? Upgrade | [,0.6.18) |
calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database. Affected versions of this package are vulnerable to Improper Access Control due to improper HTML rendering, when the user doesn't have view permissions to read the name of a private shelf, the server continues to render the HTML containing How to fix Improper Access Control? Upgrade | [,0.6.16) |
calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) due to improper fix CVE-2022-0767, which makes it possible to be bypassed via the IPV4/IPV4 embedding. How to fix Server-side Request Forgery (SSRF)? Upgrade | [,0.6.18) |
calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) due to an incomplete SSRF protection that can be bypassed via an HTTP redirect. An HTTP server that is set up to respond with a 302 redirect may redirect a request to How to fix Server-side Request Forgery (SSRF)? Upgrade | [,0.6.17) |
calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) due to an incomplete fix for CVE-2022-0339. The blacklist does not check for How to fix Server-side Request Forgery (SSRF)? Upgrade | [,0.6.17) |
calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database. Affected versions of this package are vulnerable to Improper Access Control. This is caused because low-level users can create a new shelf with public mode. How to fix Improper Access Control? Upgrade | [,0.6.16) |
calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of safe statement. How to fix Cross-site Scripting (XSS)? Upgrade | [,0.6.16) |
calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization of How to fix Server-side Request Forgery (SSRF)? Upgrade | [,0.6.16) |