CVE-2025-46338 | advplyr audiobookshelf up to 2.20.x Error Message /api/upload libraryId cross site scripting
A vulnerability was found in advplyr audiobookshelf up to 2.20.x. It has been classified as problematic. Affected is an unknown function of the file /api/upload of the component Error Message Handler. The manipulation of the argument libraryId leads to cross site scripting.
This vulnerability is traded as CVE-2025-46338. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.