github.com
https://github.com/advplyr/audiobookshelf/assets/36849099/46f6dfe0-9860-4ec0-a987-b3a553f7e45d CVE-2024-35236
MEDIUM
Audiobookshelf Cross-Site-Scripting vulnerability via crafted ebooks
Record summary
CVE-2024-35236 has a selected CVSS score of 4.8 (medium).
Description
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Attacking a user with high privileges (upload, creation of libraries) can lead to remote code execution (RCE) in the worst case. This was tested on version 2.9.0 on Windows, but an arbitrary file write is powerful enough as is and should easily lead to RCE on Linux, too. Version 2.10.0 contains a patch for the vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 28, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
audiobookshelfBrowse advplyr / audiobookshelfDefault status: unknown | CVE List | Before 2.10.0 | affected |
| < 2.10.0 | affected |
References
5github.com
https://github.com/advplyr/audiobookshelf/blob/04ed4810fdfcafc2e82db536edc5870e3f937d00/client/components/readers/EpubReader.vue github.com
https://github.com/advplyr/audiobookshelf/commit/ce7f891b9b2cb57c6644aaf96f89a8bda6307664 github.com
https://github.com/advplyr/audiobookshelf/releases/tag/v2.10.0 github.comConfirmation
https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-7j99-76cj-q9pg