PHP Object Instantiation Vulnerability in Ampache Software by Ampache Team
CVE-2017-18375
8.8HIGH
What is CVE-2017-18375?
The Ampache 3.8.3 application contains a security vulnerability that allows unauthorized PHP object instantiation through specific scripts, namely democratic.ajax.php and democratic.class.php. This flaw could potentially enable an attacker to execute arbitrary PHP code, leading to various forms of exploitation and compromising the security of the systems running the affected version.