Vulnerabilities (CVE)

Filtered by vendor Calibre-web Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-4164 1 Calibre-web Project 1 Calibre-web 2022-01-22 6.8 MEDIUM 8.8 HIGH
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-25965 1 Calibre-web Project 1 Calibre-web 2021-11-17 6.8 MEDIUM 8.8 HIGH
In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the application.