Private Shelf Information Disclosure Vulnerability Affects Calibre-Web
CVE-2021-3986
4.3MEDIUM
What is CVE-2021-3986?
A vulnerability identified in Janeczku's Calibre-Web allows unauthorized users to access the names of private shelves that belong to others. This issue arises due to improper error handling, specifically in the file shelf.py at line 221. When a user attempts to remove a book from a shelf they do not own, the application inadvertently discloses the name of that private shelf through an error message. This flaw not only highlights potential privacy breaches but also underscores the necessity for robust access controls within the application to safeguard user data against unauthorized access.
Affected Version(s)
janeczku/calibre-web <= unspecified