漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
calibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation Modification
Vulnerability Description
calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_write_access() before update_annotations() passes attacker-controlled JSON to db.merge_annotations_for_book(), which allows a readonly user or an anonymous user on an unauthenticated deployment to persist unauthorized book annotation changes. This issue is fixed in version 9.12.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
Kovidgoyal calibre 授权问题漏洞
Vulnerability Description
Kovidgoyal calibre是Kovidgoyal个人开发者的一款电子书管理软件。 Kovidgoyal calibre 9.12.0之前版本存在授权问题漏洞,该漏洞源于calibre Content Server的/book-update-annotations端点(src/calibre/srv/books.py)缺少写访问权限检查,可能允许只读用户或匿名用户持久化未授权的书注解更改。
CVSS Information
N/A
Vulnerability Type
N/A