Description
In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the application.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to 0.6.14
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-12804 | In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the application. |
References
History
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Janeczku
Janeczku calibre-web |
|
| CPEs | cpe:2.3:a:janeczku:calibre-web:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Calibre-web Project
Calibre-web Project calibre-web |
Janeczku
Janeczku calibre-web |
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2025-04-30T15:46:00.249Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25965
Updated: 2024-08-03T20:19:18.947Z
Status : Modified
Published: 2021-11-16T10:15:06.947
Modified: 2024-11-21T05:55:41.447
Link: CVE-2021-25965
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD