Ampache Vulnerability Affects Token Parsing, Could Enable CSRF Attacks
CVE-2024-51484

8.1HIGH

Key Information:

Vendor

Ampache

Status
Vendor
CVE Published:
11 November 2024

What is CVE-2024-51484?

The Ampache platform, a widely used web-based audio and video streaming solution, is affected by a vulnerability linked to inadequate validation of Cross-Site Request Forgery (CSRF) tokens. This flaw allows attackers to perform unauthorized actions on behalf of users or administrators by sending malicious requests. While the functionality of Ampache remains intact, this security issue poses a significant risk to site integrity and control. Users are strongly encouraged to upgrade to version 7.0.1 or later, as no alternative mitigations are available.

Affected Version(s)

ampache < 7.0.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.