Ampache Web-Based Audio/Video Streaming Application Vulnerability
CVE-2024-51490
9CRITICAL
Key Information:
- Vendor
- Ampache
- Status
- Ampache
- Vendor
- CVE Published:
- 11 November 2024
Summary
Ampache, a widely used web-based audio and video streaming application, has a vulnerability in the interface section of its menu where users can modify the 'Custom URL - Logo'. This section fails to properly sanitize input, allowing for potentially malicious strings that can execute JavaScript. As a result, attackers could manipulate the application by injecting arbitrary JavaScript code, raising serious security concerns for users. Ampache has released version 7.0.1 to address this issue, and all users are strongly encouraged to perform the upgrade. Currently, there are no known workarounds to mitigate this vulnerability.
Affected Version(s)
ampache < 7.0.1
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database