Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34943
HistoryApr 04, 2022 - 12:20 p.m.

Improper Access Control

2022-04-0412:20:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
27
calibreweb
vulnerability
access control
rendering
html
server
user permissions
private shelves

EPSS

0.001

Percentile

21.4%

calibreweb is vulnerable to improper access control. The vulnerability exists because the server doesn’t properly validate the user permissions when rendering HTML containing shelf name which allows an attacker to gain access to names of all private shelves.

EPSS

0.001

Percentile

21.4%

Related for VERACODE:34943