Description

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Attacking a user with high privileges (upload, creation of libraries) can lead to remote code execution (RCE) in the worst case. This was tested on version 2.9.0 on Windows, but an arbitrary file write is powerful enough as is and should easily lead to RCE on Linux, too. Version 2.10.0 contains a patch for the vulnerability.

INFO

Published Date :

2024-05-27T17:03:46.175Z

Last Modified :

2024-08-02T03:07:46.867Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-35236 vulnerability.

Vendors Products
Advplyr
  • Audiobookshelf
Audiobookshelf
  • Audiobookshelf

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact