Weak Password Requirements in janeczku/calibre-web
CVE-2023-2106
9.8CRITICAL
Summary
The Calibre-Web application developed by Janeczku exhibits insecure password practices that can lead to unauthorized access. Before version 0.6.20, the system allowed users to set weak passwords, significantly increasing the risk of credential theft and account compromise. This vulnerability underscores the need for stringent password policies to safeguard user data and maintain system integrity. Users are advised to update to the latest version and reinforce their security measures.
Affected Version(s)
janeczku/calibre-web < 0.6.20
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved