Improper Access Control in Pypi calibreweb prior to 0.6.16.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://huntr.dev/bounties/8f27686f-d698-4ab6-8ef0-899125792f13 | patch exploit third party advisory issue tracking |
https://github.com/janeczku/calibre-web/commit/0c0313f375bed7b035c8c0482bbb09599e16bfcf | third party advisory patch |