PT-2022-20301 · Unknown · Calibre-Web

Iman Sharafaldin

·

Published

2022-05-16

·

Updated

2024-11-19

·

CVE-2022-30765

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Calibre-Web versions prior to 0.6.18
Description The issue allows for SQL Injection in the user table.
Recommendations For versions prior to 0.6.18, update to version 0.6.18 or later to resolve the issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-30765
GHSA-8PPF-X4GR-2X7G

Affected Products

Calibre-Web