Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
crocodilestick Calibre-Web-Automated Admin Endpoint cwa_functions.py missing authentication
Vulnerability Description
A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Calibre-Web Automated 授权问题漏洞
Vulnerability Description
Calibre-Web Automated是CrocodileStick个人开发者的一款自托管数字图书馆管理工具。 Calibre-Web Automated 4.0.6及之前版本存在授权问题漏洞,该漏洞源于Admin Endpoint组件中文件cps/cwa_functions.py的未知功能存在身份验证缺失,攻击者可通过远程发起攻击。
CVSS Information
N/A
Vulnerability Type
N/A