Safety vulnerability ID: 54414
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of Calibreweb are vulnerable to server-side request forgery (SSRF). This is due to an incomplete fix for CVE-2022-0339. The blacklist does not check for `0.0.0.0`, which would result in a payload of `0.0.0.0` resolving to `localhost`.
Affected functions: calibreweb.cps.helper.save_cover_from_url.
Latest version: 0.6.24
Web app for browsing, reading and downloading eBooks stored in a Calibre database.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application