CVE-2024-7008
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Aug 6, 2024
Updated: Aug 19, 2024
CWE ID 79
Summary
CVE-2024-7008 is a newly disclosed vulnerability that affects Calibre versions up to 7.15.0. An attacker can exploit this issue by introducing unsanitized user-input, leading to reflected cross-site scripting (XSS) attacks. Successful exploitation enables the attacker to execute malicious scripts in the user's browser, potentially leading to data theft, session hijacking, or other unintended actions. Users are advised to upgrade to the latest version of Calibre to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share