Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34972
HistoryApr 05, 2022 - 10:30 a.m.

Server-Side Request Forgery (SSRF)

2022-04-0510:30:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
server-side request forgery
calibreweb
helper.py
internal endpoints
network access vulnerability

EPSS

0.002

Percentile

51.4%

calibreweb is vulnerable to server-side request forgery. The vulnerability exists in save_cover_from_url in helper.py because the internal end points are not properly validated which allows an attacker to access the devices running on the same network.

EPSS

0.002

Percentile

51.4%

Related for VERACODE:34972