Ampache Web-Based Audio/Video Streaming Application Vulnerability
CVE-2024-51490
9CRITICAL
What is CVE-2024-51490?
Ampache, a widely used web-based audio and video streaming application, has a vulnerability in the interface section of its menu where users can modify the 'Custom URL - Logo'. This section fails to properly sanitize input, allowing for potentially malicious strings that can execute JavaScript. As a result, attackers could manipulate the application by injecting arbitrary JavaScript code, raising serious security concerns for users. Ampache has released version 7.0.1 to address this issue, and all users are strongly encouraged to perform the upgrade. Currently, there are no known workarounds to mitigate this vulnerability.
Affected Version(s)
ampache < 7.0.1