VDB
CVE-2024-7009
CVE-2024-7009
PUBLISHED
CVSS 4.199999809265137 MEDIUM
Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.
EPSS 8.42% · 92.5th percentile
Risk Scores
CVSS 3.1
4.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Score
8.42%
92.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Calibre | Calibre | 7.15.0 |
| calibre-ebook | calibre | 0 |
| kovidgoyal | calibre | 0 |
Exploit Intelligence
Timeline
- Aug 6, 2024 EPSS Score
- Aug 6, 2024 CVE Published
- Aug 6, 2024 CVE Updated
- Aug 27, 2024 EPSS Score
- Sep 17, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 29, 2024 EPSS Score
- Nov 19, 2024 EPSS Score
- Nov 19, 2024 Coalition ESS Score
- Nov 29, 2024 Coalition ESS Score
- Dec 11, 2024 EPSS Score
- Jan 1, 2025 EPSS Score