Beveiligingsadvies

CVE-2025-46338

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-04-29 04:34:44
Laatst bijgewerkt 2025-04-29 13:37:57
Toegewezen door GitHub_M
CVSS-score 6.9
Status PUBLISHED

Beschrijving

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulnerability in the `/api/upload` endpoint allows an attacker to perform a reflected cross-site scripting (XSS) attack by submitting malicious payloads in the `libraryId` field. The unsanitized input is reflected in the server’s error message, enabling arbitrary JavaScript execution in a victim's browser. This issue has been patched in version 2.21.0.