CVE-2023-46303: SSRF
Published Oct 22, 2023
·Updated
linktolocalpath in ebooks/conversion/plugins/htmlinput.py in calibre before 6.19.0 can, by default, add resources outside of the document root.
Affected Software
1 affected component
Calibre-ebook Calibre<6.19.0
Event History
Oct 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-46303.
2
What is the title of this vulnerability?
The title of this vulnerability is 'link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can by default add resources outside of the document root.'
3
What software is affected by this vulnerability?
The software affected by this vulnerability is Calibre version up to exclusive 6.19.0.
4
What is the severity level of this vulnerability?
The severity level of this vulnerability is high with a CVSS score of 7.5.
5
How can this vulnerability be exploited?
This vulnerability can be exploited by adding resources outside of the document root using the 'link_to_local_path' function.