CVE-2021-3986

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 15, 2024
CWE ID 122

Summary

CVE-2021-3986 is a vulnerability affecting the calibre-web application by janeczku. This issue permits unauthorized users to gain insight into the names of private shelves belonging to other users. The flaw is located in the shelf.py file at line 221, where a name of a shelf is revealed in an error message when a user tries to delete a book from a shelf they do not own. This exposure of private information poses a risk to all versions of calibre-web prior to the application of the fix.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Adobe Acrobat DC
  • Adobe Acrobat Reader
  • Adobe Acrobat
  • Adobe Acrobat Reader DC

Affected Vendors

  • Adobe