CVE-2024-7009: Calibre SQL Injection
Published Aug 6, 2024
·Updated
Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.
Affected Software
1 affected component
Calibre-ebook Calibre<=7.15.0
Remediation
Event History
Aug 6, 2024
CVE Published
via MITRE·03:40 AM
Data Sourced
via MITRE·03:40 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7009?
CVE-2024-7009 is classified as a high severity vulnerability due to its potential for SQL injection.
2
How do I fix CVE-2024-7009?
To remediate CVE-2024-7009, update to a version of Calibre greater than 7.15.0 that includes the necessary security patches.
3
What type of vulnerability is CVE-2024-7009?
CVE-2024-7009 is an SQL injection vulnerability resulting from unsanitized user input.
4
Who is affected by CVE-2024-7009?
CVE-2024-7009 affects users of Calibre versions 7.15.0 and earlier with permission to perform full-text searches.
5
What are the potential impacts of CVE-2024-7009?
The potential impacts of CVE-2024-7009 include unauthorized data access, data manipulation, and compromise of the SQLite database.