Calibre-Web before 0.6.18 allows user table SQL Injection.
| Software | From | Fixed in |
|---|---|---|
calibreweb
|
- | 0.6.18 |
| janeczku / calibre-web | 0.6.18 | 0.6.18.x |