CVE-2024-35236: Audiobookshelf Cross-Site-Scripting vulnerability via crafted ebooks
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Attacking a user with high privileges (upload, creation of libraries) can lead to remote code execution (RCE) in the worst case. This was tested on version 2.9.0 on Windows, but an arbitrary file write is powerful enough as is and should easily lead to RCE on Linux, too. Version 2.10.0 contains a patch for the vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35236?
CVE-2024-35236 has a high severity due to its potential for remote code execution when malicious scripts are executed in the browsing context.
How do I fix CVE-2024-35236?
To fix CVE-2024-35236, upgrade to Audiobookshelf version 2.10.0 or later.
Who is affected by CVE-2024-35236?
CVE-2024-35236 affects users of Audiobookshelf versions prior to 2.10.0 that open ebooks containing malicious scripts.
What kind of impact does CVE-2024-35236 have?
The impact of CVE-2024-35236 can lead to the execution of arbitrary code, especially if a user with high privileges is compromised.
Can CVE-2024-35236 be exploited remotely?
Yes, CVE-2024-35236 can be exploited remotely if an attacker tricks a user into opening a specially crafted ebook.