Lucene search

K
osvGoogleOSV:CVE-2021-25964
HistoryOct 04, 2021 - 3:15 p.m.

CVE-2021-25964

2021-10-0415:15:07
Google
osv.dev
2
calibre-web
stored xss
metadata

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

19.4%

In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered.

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

19.4%

Related for OSV:CVE-2021-25964