Ampache CSRF Token Validation Vulnerability
CVE-2024-51487
8.1HIGH
What is CVE-2024-51487?
Ampache, an application designed for audio and video streaming, has been found to have a vulnerability in its token parsing mechanism related to Cross-Site Request Forgery (CSRF). The flaw arises from the improper validation of CSRF tokens when users activate or deactivate the catalog feature. This oversight makes it possible for malicious actors to execute CSRF attacks, allowing unauthorized changes to site functionalities that should be restricted to administrators. The identified issue has been rectified in version 7.0.1, and it’s crucial for all users to update their installations, as there are no alternative workarounds available to mitigate this risk.
Affected Version(s)
ampache < 7.0.1