Unauthorized Actions via Public Shelf Creation in Calibre-Web
CVE-2021-3987
4.3MEDIUM
What is CVE-2021-3987?
An access control vulnerability in Janeczku's Calibre-Web application permits users lacking the required public shelf permissions to create public shelves. The issue arises from the 'create_shelf' method within 'shelf.py', which fails to validate user permissions effectively. As a result, this oversight could allow unauthorized users to perform actions intended for permitted users, posing a security risk to the integrity of user data and shelf management.
Affected Version(s)
janeczku/calibre-web <= unspecified