Calibre是印度Kovid Goyal个人开发者的一个开源免费的全能电子书阅读管理与格式转换工具。 Calibre 7.15.0版本及之前版本存在安全漏洞,该漏洞源于用户输入清理不当,允许攻击者执行反射型跨站脚本攻击。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | It is possible to inject arbitrary JavaScript code into the /browse endpoint of the Calibre content server, allowing an attacker to craft a URL that when clicked by a victim, will execute the attacker’s JavaScript code in the context of the victim’s browser. If the Calibre server is running with authentication enabled and the victim is logged in at the time, this can be used to cause the victim to perform actions on the Calibre server on behalf of the attacker. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-7008.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2024-6782 | 9.8 CRITICAL | Calibre 安全漏洞 |
| CVE-2024-6781 | 7.5 HIGH | Calibre 安全漏洞 |
| CVE-2024-7009 | 4.2 MEDIUM | Calibre 安全漏洞 |
暂无评论