Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2024-7008Cross-site Scripting in Calibre

Severity
6.1MEDIUMNVD
EPSS
13.4%
top 5.78%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedAug 6

Description

Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

debiandebian/calibre< calibre 6.13.0+repack-2+deb12u4 (bookworm)
Debiancalibre/calibre< 5.12.0+dfsg-1+deb11u2+3
CVEListV5calibre/calibre7.15.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5q8g-5hhx-x3c8: Unsanitized user-input in Calibre <= 72024-08-06
OSV
CVE-2024-7008: Unsanitized user-input in Calibre <= 72024-08-06

💥Exploits & PoCs

1
Nuclei
Calibre <= 7.15.0 - Reflected Cross-Site Scripting (XSS)

📋Vendor Advisories

1
Debian
CVE-2024-7008: calibre - Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected...2024

💬Community

1
Bugzilla
CVE-2024-35974 kernel: block: fix q-&gt;blkg_list corruption during disk rebind2024-05-20
CVE-2024-7008 — Cross-site Scripting in Debian Calibre | cvebase