CVE-2024-7008: Calibre Reflected Cross-Site Scripting (XSS)
Published Aug 6, 2024
·Updated
Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.
Affected Software
1 affected component
Calibre-ebook Calibre<=7.15.0
Remediation
Event History
Aug 6, 2024
CVE Published
via MITRE·03:40 AM
Data Sourced
via MITRE·03:40 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7008?
CVE-2024-7008 has a medium severity level due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2024-7008?
To fix CVE-2024-7008, upgrade Calibre to the latest version beyond 7.15.0 where the vulnerability is addressed.
3
Which versions of Calibre are affected by CVE-2024-7008?
CVE-2024-7008 affects Calibre versions up to and including 7.15.0.
4
What types of attacks can CVE-2024-7008 facilitate?
CVE-2024-7008 can facilitate reflected cross-site scripting (XSS) attacks due to unsanitized user input.
5
Who is impacted by CVE-2024-7008?
Users of Calibre versions 7.15.0 or earlier are at risk from the vulnerabilities introduced by CVE-2024-7008.