Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-39307

Опубликовано: 28 июн. 2024
Источник: nvd
CVSS3: 3.5
EPSS Низкий

Описание

Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Kavita doesn't sanitize or sandbox the contents of epubs, allowing scripts inside ebooks to execute. This vulnerability was patched in version 0.8.1.

EPSS

Процентиль: 25%
0.00089
Низкий

3.5 Low

CVSS3

Дефекты

CWE-79

EPSS

Процентиль: 25%
0.00089
Низкий

3.5 Low

CVSS3

Дефекты

CWE-79