CVE-2024-7009
CVSS V2 None
CVSS V3 None
Description
Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.
Overview
- CVE ID
- CVE-2024-7009
- Assigner
- STAR_Labs
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-08-06T03:40:33.075Z
- Last Modified Date
- 2024-08-06T03:40:33.075Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://starlabs.sg/advisories/24/24-7009/ | third-party-advisory |
https://github.com/kovidgoyal/calibre/commit/d56574285e8859d3d715eb7829784ee74337b7d7 | patch |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-7009 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7009 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-08-06 13:05:22 | Added to TrackCVE |