Web Server Configuration Vulnerability in MyBooks by PoxenStudio
CVE-2026-45273
What is CVE-2026-45273?
MyBooks, an ebook management web server developed by PoxenStudio, contains a vulnerability within its AdminSettings.post handler, which allows authenticated regular users to manipulate server configuration settings without proper permissions. This oversight results from a missing check on the self.admin_user property, permitting unauthorized changes to critical aspects such as SMTP credentials, OAuth client secrets, and security feature flags. Additionally, the flawed authentication process fails to prevent registered but unactivated accounts from accessing the vulnerable handler. Successful exploitation can lead to unauthorized disclosure of sensitive information, disruption of application functionality, service interruptions, and potential code-injection attacks. This vulnerability is addressed in version 3.42.0.
Affected Version(s)
talebook < 3.42.0
