CVE-2021-25964
04.10.2021, 15:15
In Calibre-web application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in Metadata. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered.
Vendor | Product | Version |
---|---|---|
janeczku | calibre-web | 0.6.0 ≤ 𝑥 < 0.6.12 |
𝑥
= Vulnerable software versions
References