CVE-2024-7009SQL Injection in Calibre

CWE-89SQL Injection4 documents4 sources
Severity
7.1HIGHNVD
EPSS
8.4%
top 7.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 6

Description

Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NExploitability: 2.8 | Impact: 4.2

Affected Packages4 packages

debiandebian/calibre< calibre 6.13.0+repack-2+deb12u4 (bookworm)
Debiancalibre/calibre< 5.12.0+dfsg-1+deb11u2+3
CVEListV5calibre/calibre7.15.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mc4x-r58f-6h93: Unsanitized user-input in Calibre <= 72024-08-06
OSV
CVE-2024-7009: Unsanitized user-input in Calibre <= 72024-08-06

📋Vendor Advisories

1
Debian
CVE-2024-7009: calibre - Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perf...2024
CVE-2024-7009 — SQL Injection in Debian Calibre | cvebase