CVE-2023-47619

HIGH

audiobookshelf < 2.4.3 - Authenticated Server-Side Request Forgery and Arbitrary File Read/Delete via Update Permission

Title source: llm
STIX 2.1

Description

Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrary files, delete arbitrary files and send a GET request to arbitrary URLs and read the response. This issue may lead to Information Disclosure. As of time of publication, no patches are available.

Scores

CVSS v3 8.1
EPSS 0.0061
EPSS Percentile 44.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-200 CWE-918
Status published
Products (1)
audiobookshelf/audiobookshelf < 2.4.3
Published Dec 13, 2023
Tracked Since Feb 18, 2026