Beveiligingsadvies

CVE-2024-39307

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-06-28 20:44:53
Laatst bijgewerkt 2024-08-02 04:19:20
Toegewezen door GitHub_M
CVSS-score 3.5
Status PUBLISHED

Beschrijving

Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Kavita doesn't sanitize or sandbox the contents of epubs, allowing scripts inside ebooks to execute. This vulnerability was patched in version 0.8.1.