Описание
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the create_shelf method in shelf.py not verifying if the user has the necessary permissions to create a public shelf. This issue can lead to unauthorized actions being performed by users.
Уязвимые конфигурации
Конфигурация 1Версия до 0.6.15 (исключая)
cpe:2.3:a:janeczku:calibre-web:*:*:*:*:*:*:*:*
EPSS
Процентиль: 30%
0.00109
Низкий
5.4 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-284
CWE-862
Связанные уязвимости
CVSS3: 4.3
debian
около 1 года назад
An improper access control vulnerability exists in janeczku/calibre-we ...
CVSS3: 5.4
github
около 1 года назад
Improper Access Control in janeczku/calibre-web
EPSS
Процентиль: 30%
0.00109
Низкий
5.4 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-284
CWE-862