Calibre-Web 0.6.6 allows authentication bypass because of...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Nov 19, 2024
Description
Published by the National Vulnerability Database
May 4, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Nov 19, 2024
Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.
References