PT-2024-28432 · Kavita · Kavita

Thegebirge

·

Published

2024-06-28

·

Updated

2024-07-01

·

CVE-2024-39307

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kavita versions prior to 0.8.1
Description The issue arises when an ebook containing malicious scripts is opened, leading to code execution within the browsing context. This occurs because Kavita does not sanitize or sandbox the contents of epubs, allowing scripts inside ebooks to execute.
Recommendations For versions prior to 0.8.1, update to version 0.8.1 to resolve the issue. As a temporary workaround, consider avoiding the use of ebooks from untrusted sources until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-39307
GHSA-R4QC-3W52-2V84

Affected Products

Kavita