CVE-2024-7009

Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.
Configurations

Configuration 1 (hide)

cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:*

History

19 Aug 2024, 17:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.2
v2 : unknown
v3 : 7.1
CPE cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:*
First Time Calibre-ebook calibre
Calibre-ebook
References () https://github.com/kovidgoyal/calibre/commit/d56574285e8859d3d715eb7829784ee74337b7d7 - () https://github.com/kovidgoyal/calibre/commit/d56574285e8859d3d715eb7829784ee74337b7d7 - Patch
References () https://starlabs.sg/advisories/24/24-7009/ - () https://starlabs.sg/advisories/24/24-7009/ - Exploit, Mitigation, Third Party Advisory

06 Aug 2024, 16:30

Type Values Removed Values Added
Summary
  • (es) La entrada de usuario no sanitizada en Calibre &lt;= 7.15.0 permite a los usuarios con permisos realizar búsquedas de texto completo para lograr la inyección SQL en la base de datos SQLite.

06 Aug 2024, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-06 04:16

Updated : 2024-08-19 17:18


NVD link : CVE-2024-7009

Mitre link : CVE-2024-7009

CVE.ORG link : CVE-2024-7009


JSON object : View

Products Affected

calibre-ebook

  • calibre
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')