Description

An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the user has the necessary permissions to create a public shelf. This issue can lead to unauthorized actions being performed by users.

INFO

Published Date :

2024-11-15T10:52:29.478Z

Last Modified :

2024-11-15T18:28:12.925Z

Source :

@huntr_ai
AFFECTED PRODUCTS

The following products are affected by CVE-2021-3987 vulnerability.

Vendors Products
Calibre-web Project
  • Calibre-web
Janeczku
  • Calibre-web
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2021-3987.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact