Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-7008 PoC — Calibre Reflected Cross-Site Scripting (XSS)

Source
Associated Vulnerability
Title:Calibre Reflected Cross-Site Scripting (XSS) (CVE-2024-7008)
Description:Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.
Description
It is possible to inject arbitrary JavaScript code into the /browse endpoint of the Calibre content server, allowing an attacker to craft a URL that when clicked by a victim, will execute the attacker’s JavaScript code in the context of the victim’s browser. If the Calibre server is running with authentication enabled and the victim is logged in at the time, this can be used to cause the victim to perform actions on the Calibre server on behalf of the attacker.
File Snapshot

id: CVE-2024-7008 info: name: Calibre <= 7.15.0 - Reflected Cross-Site Scripting (XSS) author: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →