Kavita - Local File Inclusion
Kavita - Path Traversal is vulnerable to local file inclusion via abusing the Path Traversal filename parameter of the /api/image/cover-upload.
KavitaPoC 已收录
CVSS7.5
Cross-platform e-book/manga/comic/pdf server and web reader with user management, ratings and reviews, and metatdata support.
共找到 2 条公开漏洞记录
Kavita - Path Traversal is vulnerable to local file inclusion via abusing the Path Traversal filename parameter of the /api/image/cover-upload.
Kavita before 0.5.4.1 is susceptible to server-side request forgery in GitHub repository kareadita/kavita. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.