Ampache Web-Based Audio/Video Streaming Application Vulnerability
CVE-2024-51490

9CRITICAL

Key Information:

Vendor
Ampache
Status
Ampache
Vendor
CVE Published:
11 November 2024

Summary

Ampache, a widely used web-based audio and video streaming application, has a vulnerability in the interface section of its menu where users can modify the 'Custom URL - Logo'. This section fails to properly sanitize input, allowing for potentially malicious strings that can execute JavaScript. As a result, attackers could manipulate the application by injecting arbitrary JavaScript code, raising serious security concerns for users. Ampache has released version 7.0.1 to address this issue, and all users are strongly encouraged to perform the upgrade. Currently, there are no known workarounds to mitigate this vulnerability.

Affected Version(s)

ampache < 7.0.1

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.