Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34944
HistoryApr 04, 2022 - 1:31 p.m.

Authorization Bypass

2022-04-0413:31:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
calibreweb
authorization bypass
vulnerability
create_edit_shelf
shelf.py
user permissions
public
private shelves

EPSS

0.001

Percentile

21.4%

calibreweb is vulnerable to authorization bypass. The vulnerability exists in create_edit_shelf function in shelf.py because the server doesn’t properly validate the user permissions which allows an attacker to create and modify public and private shelves.

EPSS

0.001

Percentile

21.4%

Related for VERACODE:34944