Ampache CSRF Token Validation Vulnerability
CVE-2024-51487

8.1HIGH

Key Information:

Vendor

Ampache

Status
Vendor
CVE Published:
11 November 2024

What is CVE-2024-51487?

Ampache, an application designed for audio and video streaming, has been found to have a vulnerability in its token parsing mechanism related to Cross-Site Request Forgery (CSRF). The flaw arises from the improper validation of CSRF tokens when users activate or deactivate the catalog feature. This oversight makes it possible for malicious actors to execute CSRF attacks, allowing unauthorized changes to site functionalities that should be restricted to administrators. The identified issue has been rectified in version 7.0.1, and it’s crucial for all users to update their installations, as there are no alternative workarounds available to mitigate this risk.

Affected Version(s)

ampache < 7.0.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.