janeczku Calibre-Web
cpe:2.3:a:janeczku:calibre-web:*:*:*:*:*:*:*
- <= 0.6.26
An improper authorization vulnerability has been identified in Janeczku Calibre-Web versions through 0.6.26. The issue arises in the Endpoint component, specifically within the generate_auth_token function of the kobo_auth.py file. This vulnerability allows for unauthorized actions by manipulating the user_id argument, and can be exploited remotely. Publicly available exploits exist for this vulnerability.
Exploitation of this vulnerability allows for improper authorization, enabling persistent user impersonation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.