Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pc5g-j9j7-p4q3

Опубликовано: 02 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 1.9

Описание

Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation

A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.

Пакеты

Наименование

calibreweb

pip
Затронутые версииВерсия исправления

<= 0.6.25

Отсутствует

EPSS

Процентиль: 12%
0.0004
Низкий

1.9 Low

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.5
nvd
2 месяца назад

A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.

CVSS3: 3.5
debian
2 месяца назад

A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6. ...

EPSS

Процентиль: 12%
0.0004
Низкий

1.9 Low

CVSS4

Дефекты

CWE-79